VDB
Sign up
MEDIUM5.0

GHSA-w9pg-7c3h-fc8j

ipl/web's `ipl\Web\Common\CsrfCounterMeasure` is susceptible to CSRF

Quick fix

GHSA-w9pg-7c3h-fc8j — ipl/web: upgrade to the fixed version with the command below.

composer require ipl/web:^0.10.1

Details

### Impact Some of the recent development by Icinga is, under certain circumstances, susceptible to cross site request forgery. (CSRF)

Affected products:

* Icinga Web (>=2.12.0) * Icinga DB Web (>=1.0.0) * Icinga Notifications Web (>=0.1.0) * Icinga Web JIRA Integration (>=1.3.0)

All affected products, in any version, will be unaffected by this once `icinga-php-library` is upgraded.

### Patches Version 0.10.1 will include a fix for this. It will be published as part of the `icinga-php-library` v0.14.1 release.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/ipl/web
Introduced in: 0Fixed in: 0.10.1
Fixcomposer require ipl/web:^0.10.1

References