Explicitly Disabled CSRF Protection
Security configurations that explicitly disable CSRF protection using csrf().disable(), removing token validation for state-changing operations.
Preview example â JAVA
@Configuration
@EnableWebSecurity
public class SecurityConfig {
@Bean
public SecurityFilterChain filterChain(HttpSecurity http) throws Exception {
return http
.csrf().disable() // Vulnerable: Disables CSRF protection
.authorizeHttpRequests(auth -> auth
.requestMatchers("/api/**").authenticated()
.anyRequest().permitAll()
)
.build();
}
}