CVE-2022-42975: CSRF
socket/transport.ex in Phoenix before 1.6.14 mishandles checkorigin wildcarding. NOTE: LiveView applications are unaffected by default because of the presence of a LiveView CSRF token.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
erlang/phoenixto a version that resolves this vulnerability.Fixed in 1.6.14
Event History
Frequently Asked Questions
What is the severity of CVE-2022-42975?
CVE-2022-42975 has been classified with a severity level that indicates a potential risk primarily due to mishandled check_origin wildcarding.
How do I fix CVE-2022-42975?
To fix CVE-2022-42975, you should upgrade Phoenix to version 1.6.14 or later.
What versions of Phoenix are affected by CVE-2022-42975?
CVE-2022-42975 affects all versions of Phoenix prior to 1.6.14.
Are LiveView applications affected by CVE-2022-42975?
LiveView applications are not affected by CVE-2022-42975 by default due to the presence of a LiveView CSRF token.
What component in Phoenix is responsible for CVE-2022-42975?
The vulnerability in CVE-2022-42975 is found in the socket/transport.ex component of Phoenix.