HIGH8.8
GHSA-wmrg-w9vg-7jqx
Magento 2 Community Edition CSRF Vulnerability
Quick fix
GHSA-wmrg-w9vg-7jqx — magento/community-edition: upgrade to the fixed version with the command below.
composer require magento/community-edition:^2.1.18Details
A cross-site request forgery (CSRF) vulnerability exists in the checkout cart item of Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2. This could be exploited at the time of editing or configuration.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/magento/community-edition
Introduced in:
2.1.0Fixed in: 2.1.18Fix
composer require magento/community-edition:^2.1.18Packagist/magento/community-edition
Introduced in:
2.2.0Fixed in: 2.2.9Fix
composer require magento/community-edition:^2.2.9Packagist/magento/community-edition
Introduced in:
2.3.0Fixed in: 2.3.2Fix
composer require magento/community-edition:^2.3.2Packagist/magento/product-community-edition
Introduced in:
2.1Fixed in: 2.1.18Fix
composer require magento/product-community-edition:^2.1.18Packagist/magento/product-community-edition
Introduced in:
2.2Fixed in: 2.2.9Fix
composer require magento/product-community-edition:^2.2.9Packagist/magento/product-community-edition
Introduced in:
2.3Fixed in: 2.3.2Fix
composer require magento/product-community-edition:^2.3.2References
- https://nvd.nist.gov/vuln/detail/CVE-2019-7865[ADVISORY]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/magento/product-community-edition/CVE-2019-7865.yaml[WEB]
- https://github.com/magento/magento2[PACKAGE]
- https://magento.com/security/patches/magento-2.3.2-2.2.9-and-2.1.18-security-update-33[WEB]
- https://web.archive.org/web/20220121011306/https://magento.com/security/patches/magento-2.3.2-2.2.9-and-2.1.18-security-update-33[WEB]