Advisories for Composer/Symfony/Security-Csrf package

2018

CSRF vulnerability

The implementation of CSRF protection did not use different tokens for HTTP and HTTPS, therefore the token was subject to MITM attacks on HTTP and could then be used in HTTPS context to do CSRF attacks.