VDB
Sign up
HIGH8.8

GHSA-cwhm-272p-3wj9

Yii Framework Cross-Site Request Forgery (CSRF)

Quick fix

GHSA-cwhm-272p-3wj9 — yiisoft/yii2: upgrade to the fixed version with the command below.

composer require yiisoft/yii2:^2.0.14

Details

In Yii Framework 2.x before 2.0.14, the switchIdentity function in web/User.php did not regenerate the CSRF token upon a change of identity.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/yiisoft/yii2
Introduced in: 2.0Fixed in: 2.0.14
Fixcomposer require yiisoft/yii2:^2.0.14
Packagist/yiisoft/yii2-dev
Introduced in: 2.0Fixed in: 2.0.14
Fixcomposer require yiisoft/yii2-dev:^2.0.14

References