Skip to content

Conversation

@Lemongrass3110
Copy link
Member

Bumped PHP minimum version to 7.3.0
This was required to have the new function signature available, which allows setting the samesite attribute natively PHP 7.3.0 was introduced in 2018 - 7 years ago - it is already out of support since 2021 - 4 years ago. Updating to a more recent PHP version is recommended.

Bumped recommended PHP and MySQL version to latest available version

This update is aimed to resolve a security vulnerability reported by @marksocrates1111

Bumped PHP minimum version to 7.3.0
This was required to have the new function signature available, which allows setting the samesite attribute natively
PHP 7.3.0 was introduced in 2018 - 7 years ago - it is already out of support since 2021 - 4 years ago.
Updating to a more recent PHP version is recommended.

Bumped recommended PHP and MySQL version to latest available version

This update is aimed to resolve a security vulnerability reported by @marksocrates1111
@marksocrates1111
Copy link

Hi @Lemongrass3110 and the rAthena team,

Thank you for the quick response and for deploying the fix.

Setting the session cookie attribute 'samesite' => 'Strict' correctly mitigates the CSRF vulnerability I reported. This will prevent the browser from sending the cookie on cross-domain requests and block the attack.

I appreciate you taking the report seriously and patching it so quickly.

As a final step, has a CVE ID been requested for this vulnerability?

Thank you and have a great day ahead!

Mark

@Lemongrass3110 Lemongrass3110 merged commit e3f130c into master Oct 28, 2025
7 checks passed
@Lemongrass3110 Lemongrass3110 deleted the hotfix/cookie_restrictions branch October 28, 2025 09:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants