https://portswigger.net/daily-swig/bittersweet-symfony-devs-accidentally-turn-off-csrf-protection-in-php-framework The Daily Swig [ ] ( ) ( ) ( ) ( ) ( ) ( ) ( ) ( ) Regions Hacking News Data Breaches Cyber-attacks Vulnerabilities Bug Bounties More About Africa Asia Europe Middle East Latin America North America Oceania View all US news APT focus Take a closer look at Iran's state-sponsored hacking groups Regions Latest Hacking News Hacking Tools Hacking Techniques Pen Testing Cloud Security Database Security Email Security Network Security View all hacking news Hacker-powered security Human error bugs increasingly making a splash, study indicates Hacking news Latest Data Breaches Data Leak Organizations Enterprise Security View all data breach news In focus Software supply chain attacks - everything you need to know Data Breaches Latest Cyber-attacks Cybercrime Cyber Warfare DDoS Attacks Supply Chain Attacks View all cyber-attack news Special report North Korean cyber-threat groups become top-tier adversaries Cyber Attacks Latest Vulnerabilities Zero-Day News RCE XSS SQL Injection SSRF CSRF XS Leaks View all security vulnerability news What's in a (domain) name? How expired web domains are helping criminal hacking campaigns Vulnerabilities Bug Bounty News VDP News Research OSINT View all bug bounty news Bug Bounty Radar The latest programs for January 2022 Bug bounties Interviews Analysis Research Deep Dives Browsers Ransomware Phishing Malware Encryption Privacy Mobile IoT Policy and Legislation Machine learning DNS Open Source Hardware Authentication Events View all infosec industry news Cybersecurity conferences A schedule of events in 2021 and beyond More topics Bittersweet Symfony: Devs accidentally turn off CSRF protection in PHP framework John Leyden 03 February 2022 at 16:52 UTC CSRF Vulnerabilities PHP Twitter WhatsApp Facebook Reddit LinkedIn Email Inadvertent defense downgrade quickly reverted Symfony CSRF protection removed Developers of the Symfony PHP framework have reversed a recent change that inadvertently turned off protection against cross-site request forgery (CSRF) attacks. Symfony is a popular PHP framework for web and console applications. The Symfony form component of the open source software features a CSRF protection mechanism that relies on a random token injected in the form. This protection can be enabled or disabled by changing the configuration setup of the framework. Protection was enabled by default until a recent change in how the configuration was loaded meant that CSRF protection was turned off and needed to be explicitly enabled. RELATED Web cache poisoning bug discovered in Symfony PHP framework CSRF vulnerabilities creates a mechanism for attackers to trick users into carrying out actions they did not intend to perform. The problem arises in cases where it's possible for different websites to interfere with each other. Modern browsers such as Chrome as well as web development frameworks such as Symfony feature built-in protection against CSRF attacks. Users of affected versions of Symfony (5.3.14 and earlier, 5.4.0-5.4.3, and 6.0.0-6.03) need to upgrade to patched versions, as explained in an advisory posted on GitHub. The issue - tracked as CVE-2022-23501 - notched a CVSS score of 8.1. Because of its high impact early remediation is recommended. YOU MAY ALSO LIKE Chrome to bolster CSRF protections with preflight checks on private network requests CSRF Vulnerabilities PHP Secure Development Open Source Software Chrome Social Engineering Browsers DevOps DevSecOps Industry News John Leyden John Leyden @jleyden Twitter WhatsApp Facebook Reddit LinkedIn Email This page requires JavaScript for an enhanced user experience. Latest Posts Cloudflare bug bounty program goes public 03 February 2022 Cloudflare bug bounty program goes public Silicon Valley firm has paid out more than $200,000 since private program's 2018 launch SnapFuzz New fuzzing tool speeds up testing of network applications 03 February 2022 SnapFuzz New fuzzing tool speeds up testing of network applications WordPress security Serious bug in plugin Essential Addons for Elementor eliminated 02 February 2022 WordPress security Serious bug in plugin Essential Addons for Elementor eliminated Related stories This page requires JavaScript for an enhanced user experience. Bittersweet Symfony PHP framework devs accidentally turn off CSRF protection 03 February 2022 Bittersweet Symfony PHP framework devs accidentally turn off CSRF protection Cloudflare bug bounty program goes public 03 February 2022 Cloudflare bug bounty program goes public Silicon Valley firm has paid out more than $200,000 since private program's 2018 launch SnapFuzz New fuzzing tool speeds up testing of network applications 03 February 2022 SnapFuzz New fuzzing tool speeds up testing of network applications WordPress security Serious bug in plugin Essential Addons for Elementor eliminated 02 February 2022 WordPress security Serious bug in plugin Essential Addons for Elementor eliminated Burp Suite Web vulnerability scanner Burp Suite Editions Release Notes Vulnerabilities Cross-site scripting (XSS) SQL injection Cross-site request forgery XML external entity injection Directory traversal Server-side request forgery Customers Organizations Testers Developers Company About PortSwigger News Careers Contact Legal Privacy Notice Insights Web Security Academy Blog Research The Daily Swig PortSwigger Logo Follow us (c) 2022 PortSwigger Ltd.