VDB
Sign up
HIGH8.8

GHSA-wmrg-w9vg-7jqx

Magento 2 Community Edition CSRF Vulnerability

Quick fix

GHSA-wmrg-w9vg-7jqx — magento/community-edition: upgrade to the fixed version with the command below.

composer require magento/community-edition:^2.1.18

Details

A cross-site request forgery (CSRF) vulnerability exists in the checkout cart item of Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This could be exploited at the time of editing or configuration.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/magento/community-edition
Introduced in: 2.1.0Fixed in: 2.1.18
Fixcomposer require magento/community-edition:^2.1.18
Packagist/magento/community-edition
Introduced in: 2.2.0Fixed in: 2.2.9
Fixcomposer require magento/community-edition:^2.2.9
Packagist/magento/community-edition
Introduced in: 2.3.0Fixed in: 2.3.2
Fixcomposer require magento/community-edition:^2.3.2
Packagist/magento/product-community-edition
Introduced in: 2.1Fixed in: 2.1.18
Fixcomposer require magento/product-community-edition:^2.1.18
Packagist/magento/product-community-edition
Introduced in: 2.2Fixed in: 2.2.9
Fixcomposer require magento/product-community-edition:^2.2.9
Packagist/magento/product-community-edition
Introduced in: 2.3Fixed in: 2.3.2
Fixcomposer require magento/product-community-edition:^2.3.2

References