Commerce CyberSource
Anyone without logging in could manipulate the timing of messages sent back from the payment provider. This would allow them to trick the website into recording a successful payment when no money was actually taken. They could not read any private data.
- Who could do thisAnyone visiting the site. No login needed.
- Does it apply to youA site is affected if it uses the off site redirect payment method.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate Commerce CyberSource to 8.x-1.10.
For developers: what the fix changed
The fix updates the signature validation in the validateResponse function of src/Plugin/Commerce/PaymentGateway/CyberSourceSahc.php to use hash_equals. This ensures the comparison executes in constant time to prevent timing attacks.
Also in this release The release also added JWT signature verification for transient tokens in the Flex payment gateway.
src/Plugin/Commerce/PaymentGateway/CyberSourceSahc.php+26 −6 fixsrc/Plugin/Commerce/PaymentGateway/Flex.php+36 −4