MEDIUM5.9
GHSA-92x6-h2gr-8gxq
Symfony CSRF Vulnerability
Quick fix
GHSA-92x6-h2gr-8gxq — symfony/security-csrf: upgrade to the fixed version with the command below.
composer require symfony/security-csrf:^2.7.38Details
An issue was discovered in Symfony before 2.7.38, 2.8.31, 3.2.14, 3.3.13, 3.4-BETA5, and 4.0-BETA5. The current implementation of CSRF protection in Symfony (Version >=2) does not use different tokens for HTTP and HTTPS; therefore the token is subject to MITM attacks on HTTP and can then be used in an HTTPS context to do CSRF attacks.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/symfony/security-csrf
Introduced in:
2.7.0Fixed in: 2.7.38Fix
composer require symfony/security-csrf:^2.7.38Packagist/symfony/security-csrf
Introduced in:
2.8.0Fixed in: 2.8.31Fix
composer require symfony/security-csrf:^2.8.31Packagist/symfony/security-csrf
Introduced in:
3.0.0Fixed in: 3.2.14Fix
composer require symfony/security-csrf:^3.2.14Packagist/symfony/security-csrf
Introduced in:
3.3.0Fixed in: 3.3.13Fix
composer require symfony/security-csrf:^3.3.13Packagist/symfony/security
Introduced in:
2.7.0Fixed in: 2.7.38Fix
composer require symfony/security:^2.7.38Packagist/symfony/security
Introduced in:
2.8.0Fixed in: 2.8.31Fix
composer require symfony/security:^2.8.31Packagist/symfony/security
Introduced in:
3.0.0Fixed in: 3.2.14Fix
composer require symfony/security:^3.2.14Packagist/symfony/security
Introduced in:
3.3.0Fixed in: 3.3.13Fix
composer require symfony/security:^3.3.13Packagist/symfony/symfony
Introduced in:
2.7.0Fixed in: 2.7.38Fix
composer require symfony/symfony:^2.7.38Packagist/symfony/symfony
Introduced in:
2.8.0Fixed in: 2.8.31Fix
composer require symfony/symfony:^2.8.31Packagist/symfony/symfony
Introduced in:
3.0.0Fixed in: 3.2.14Fix
composer require symfony/symfony:^3.2.14Packagist/symfony/symfony
Introduced in:
3.3.0Fixed in: 3.3.13Fix
composer require symfony/symfony:^3.3.13References
- https://nvd.nist.gov/vuln/detail/CVE-2017-16653[ADVISORY]
- https://github.com/symfony/symfony/pull/24992[WEB]
- https://github.com/symfony/symfony/commit/b4dbdd7cd8732483d585eacff3428c16b07ad15e[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/security-csrf/CVE-2017-16653.yaml[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/security/CVE-2017-16653.yaml[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/symfony/CVE-2017-16653.yaml[WEB]
- https://github.com/symfony/symfony[PACKAGE]
- https://symfony.com/blog/cve-2017-16653-csrf-protection-does-not-use-different-tokens-for-http-and-https[WEB]
- https://symfony.com/cve-2017-16653[WEB]
- https://www.debian.org/security/2018/dsa-4262[WEB]