Lucene search

K
githubGitHub Advisory DatabaseGHSA-G4G7-Q726-V5HG
HistoryMay 14, 2022 - 1:14 a.m.

Symfony CSRF Token Fixation

2022-05-1401:14:35
CWE-352
GitHub Advisory Database
github.com
9
symfony
csrf
token fixation
security
component
logout
issue

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS

0.003

Percentile

68.7%

An issue was discovered in the Security component in Symfony 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x before 4.0.11. By default, a user’s session is invalidated when the user is logged out. This behavior can be disabled through the invalidate_session option. In this case, CSRF tokens were not erased during logout which allowed for CSRF token fixation.

Affected configurations

Vulners
Node
symfonysecurityRange<4.0.11
OR
symfonysecurityRange<3.4.11
OR
symfonysecurityRange<3.3.17
OR
symfonysecurityRange<2.8.41
OR
symfonysecurityRange<2.7.48
OR
symfonysecurity_httpRange<4.0.11
OR
symfonysecurity_httpRange<3.4.11
OR
symfonysecurity_httpRange<3.3.17
OR
symfonysecurity_httpRange<2.8.41
OR
symfonysecurity_httpRange<2.7.48
OR
symfonysecurity_bundleRange<4.0.11
OR
symfonysecurity_bundleRange<3.4.11
OR
symfonysecurity_bundleRange<3.3.17
OR
symfonysecurity_bundleRange<2.8.41
OR
symfonysecurity_bundleRange<2.7.48
OR
symfonysymfonyRange<3.3.17
OR
symfonysymfonyRange<4.0.11
OR
symfonysymfonyRange<3.4.11
OR
symfonysymfonyRange<2.8.41
OR
symfonysymfonyRange<2.7.48

References

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS

0.003

Percentile

68.7%