VDB
Sign up
HIGH8.8

GHSA-fx37-56v6-85q6

Silverstripe CSRF Protection Bypass via GraphQL

Quick fix

GHSA-fx37-56v6-85q6 — silverstripe/graphql: upgrade to the fixed version with the command below.

composer require silverstripe/graphql:^2.0.5

Details

In SilverStripe/GraphQL prior to 2.0.5 and 3.1.2, the previous fix for SS-2018-007 does not completely mitigate the risk of CSRF in GraphQL mutations.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/silverstripe/graphql
Introduced in: 2.0.0Fixed in: 2.0.5
Fixcomposer require silverstripe/graphql:^2.0.5
Packagist/silverstripe/graphql
Introduced in: 3.1.0Fixed in: 3.1.2
Fixcomposer require silverstripe/graphql:^3.1.2

References