GHSA-65v7-wg35-2qpm
Sylius Resource Bundle Cross-Site Request Forgery vulnerability
Quick fix
GHSA-65v7-wg35-2qpm — sylius/resource-bundle: upgrade to the fixed version with the command below.
composer require sylius/resource-bundle:^1.0.17Details
Sylius 1.0.0 to 1.0.16, 1.1.0 to 1.1.8, 1.2.0 to 1.2.1 versions of AdminBundle and ResourceBundle are affected by this security issue.
This issue has been fixed in Sylius 1.0.17, 1.1.9 and 1.2.2. Development branch for 1.3 release has also been fixed.
### Description
The following actions in the admin panel did not require a CSRF token:
- marking order’s payment as completed - marking order’s payment as refunded - marking product review as accepted - marking product review as rejected
### Resolution
The issue is fixed by adding a required CSRF token to those actions.
We also fixed `ResourceController`‘s `applyStateMachineTransitionAction` method by adding a CSRF token check. If you use that action in the API context, you can disable it by adding `csrf_protection:` false to its routing configuration
Are you affected?
Enter the version of the package you're using.
Affected packages
1.0.0Fixed in: 1.0.17composer require sylius/resource-bundle:^1.0.171.1.0Fixed in: 1.1.9composer require sylius/resource-bundle:^1.1.91.2.0Fixed in: 1.2.2composer require sylius/resource-bundle:^1.2.2References
- https://github.com/Sylius/SyliusResourceBundle/commit/9720ac5a0a39ea2c2a395ef16a94a00aa86c418b[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/sylius/sylius/2018-07-09.yaml[WEB]
- https://github.com/Sylius/SyliusResourceBundle[PACKAGE]
- https://sylius.com/blog/csrf-vulnerability-in-admin-panel[WEB]