Skip to content
GSSA-2026-04-4YYSARGITLAB-GSSA-2026-04-4YYSARApril 25, 2026
4.2 Medium

Missing HSTS and incomplete CSP directives in cobc-events

cobc-events <1.0.1 did not set Strict-Transport-Security and was missing key Content-Security-Policy directives (`frame-ancestors`, `object-src`, `base-uri`, `form-action`), enabling downgrade and clickjacking attacks.

Affected (1)

  • gelhaus-solutionscobc-events
    • ≥ 0.0.0Fixed in 1.0.1

Mitigations

Workarounds

  • Configure HSTS at the reverse proxy or CDN layer.
  • Add `X-Frame-Options: DENY` and `Content-Security-Policy: frame-ancestors 'none'` via the proxy.

Solutions

  • Upgrade cobc-events to 1.0.1 or later and serve traffic exclusively over HTTPS.

Overview

cobc-events <1.0.1 did not set Strict-Transport-Security and was missing key Content-Security-Policy directives (frame-ancestors, object-src, base-uri, form-action), enabling downgrade and clickjacking attacks.

Severity

CVSS v3
4.2 Medium
4.2
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N
Attack vector
Network
Attack complexity
High
Privileges required
None
User interaction
Required
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
None

Weaknesses (3)

References (3)

Credits (5)

  • Enno Gelhaus
    Finder · egelhaus@ennogelhaus.de
  • Enno Gelhaus
    Analyst · egelhaus@ennogelhaus.de
  • Enno Gelhaus
    Remediation developer · egelhaus@ennogelhaus.de
  • Enno Gelhaus
    Remediation reviewer · egelhaus@ennogelhaus.de
  • Claude (Anthropic) — automated audit assistant
    Tool · https://claude.com

Context

Impacts

  • TLS downgrade on first visit

    CAPEC-220
  • Clickjacking via iframe embedding

    CAPEC-103

Timeline

  1. 04/25/2026 00:00

    Internal security audit started

  2. 04/25/2026 06:00

    Vulnerability identified during audit

  3. 04/25/2026 12:00

    Patch developed and merged to main

  4. 04/25/2026 14:00

    cobc-events 1.0.1 released

  5. 04/25/2026 15:00

    Advisory published

© 2026 Gelhaus Solutions