PT-2022-6951 · Symfony · Symfony

Catalin Dan

+1

·

Published

2022-02-01

·

Updated

2024-03-06

·

CVE-2022-23601

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Symfony versions prior to the patch versions listed
Description The issue is related to insufficient authentication of executed requests in the Symfony framework, which can allow a remote attacker to perform a CSRF attack. The Symfony form component provides a CSRF protection mechanism using a random token injected in the form and stored in the session. However, due to a recent change in the configuration loading, the default behavior of enabling CSRF protection has been dropped, making applications sensitive to CSRF attacks when the protection is not explicitly enabled.
Recommendations For Symfony versions prior to the patch versions listed, update to a version that includes the patch to resolve the issue. As a temporary workaround, consider enabling the CSRF protection mechanism explicitly in the configuration to prevent CSRF attacks.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-05710
BIT-SYMFONY-2022-23601
CVE-2022-23601
GHSA-VVMR-8829-6WHX

Affected Products

Symfony