CVE-2022-23601Cross-Site Request Forgery in Symfony

Severity
8.8HIGHNVD
CNA8.1
EPSS
0.2%
top 61.22%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 1

Description

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. The Symfony form component provides a CSRF protection mechanism by using a random token injected in the form and using the session to store and control the token submitted by the user. When using the FrameworkBundle, this protection can be enabled or disabled with the configuration. If the configuration is not specified, by default, the mechanism is enabled as long as the session is enabled. In a re

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages3 packages

Packagistsymfony/framework-bundle5.3.145.3.15+2
NVDsensiolabs/symfony5.4.05.4.4+2
CVEListV5symfony/symfony5.3.14, 5.4.3, 6.0.3+2

Patches

🔴Vulnerability Details

3
CVEList
CSRF token missing in Symfony2022-02-01
GHSA
CSRF token missing in Symfony2022-02-01
OSV
CSRF token missing in Symfony2022-02-01

📋Vendor Advisories

1
Debian
CVE-2022-23601: symfony - Symfony is a PHP framework for web and console applications and a set of reusabl...2022
CVE-2022-23601 — Cross-Site Request Forgery in Symfony | cvebase