VDB
Sign up
MEDIUM6.5

GHSA-65v7-wg35-2qpm

Sylius Resource Bundle Cross-Site Request Forgery vulnerability

Quick fix

GHSA-65v7-wg35-2qpm — sylius/resource-bundle: upgrade to the fixed version with the command below.

composer require sylius/resource-bundle:^1.0.17

Details

Sylius 1.0.0 to 1.0.16, 1.1.0 to 1.1.8, 1.2.0 to 1.2.1 versions of AdminBundle and ResourceBundle are affected by this security issue.

This issue has been fixed in Sylius 1.0.17, 1.1.9 and 1.2.2. Development branch for 1.3 release has also been fixed.

### Description

The following actions in the admin panel did not require a CSRF token:

- marking order’s payment as completed - marking order’s payment as refunded - marking product review as accepted - marking product review as rejected

### Resolution

The issue is fixed by adding a required CSRF token to those actions.

We also fixed `ResourceController`‘s `applyStateMachineTransitionAction` method by adding a CSRF token check. If you use that action in the API context, you can disable it by adding `csrf_protection:` false to its routing configuration

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/sylius/resource-bundle
Introduced in: 1.0.0Fixed in: 1.0.17
Fixcomposer require sylius/resource-bundle:^1.0.17
Packagist/sylius/resource-bundle
Introduced in: 1.1.0Fixed in: 1.1.9
Fixcomposer require sylius/resource-bundle:^1.1.9
Packagist/sylius/resource-bundle
Introduced in: 1.2.0Fixed in: 1.2.2
Fixcomposer require sylius/resource-bundle:^1.2.2

References