MidnightBSD

Advisories for sensiolabs

CVE-2012-2667 MEDIUM

Session fixation vulnerability in lib/user/sfBasicSecurityUser.class.php in SensioLabs Symfony before 1.4.18 allows remote attackers to hijack web sessions via vectors related to the regenerate method and unspecified "database backed session classes."

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
sensiolabs symfony 1.4.6
sensiolabs symfony 1.4.0
sensiolabs symfony 1.4.10
sensiolabs symfony 1.4.2
sensiolabs symfony 1.4.15
sensiolabs symfony 1.4.12
sensiolabs symfony 1.4.9
sensiolabs symfony 1.4.16
sensiolabs symfony 1.4.4
sensiolabs symfony 1.4.3
sensiolabs symfony 1.4.5
sensiolabs symfony 1.4.14
sensiolabs symfony 1.4.1
sensiolabs symfony 1.4.13
sensiolabs symfony 1.4.11
sensiolabs symfony *
sensiolabs symfony 1.4.8
sensiolabs symfony 1.4.7
CVE-2012-5574 MEDIUM

lib/form/sfForm.class.php in Symfony CMS before 1.4.20 allows remote attackers to read arbitrary files via a crafted upload request.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
sensiolabs symfony 1.4.18
sensiolabs symfony 1.4.0
sensiolabs symfony 1.4.6
sensiolabs symfony 1.4.10
sensiolabs symfony 1.4.2
sensiolabs symfony 1.4.12
sensiolabs symfony 1.4.15
sensiolabs symfony 1.4.9
sensiolabs symfony 1.4.16
sensiolabs symfony 1.4.4
sensiolabs symfony 1.4.3
sensiolabs symfony 1.4.5
sensiolabs symfony 1.4.14
sensiolabs symfony 1.4.1
sensiolabs symfony 1.4.17
sensiolabs symfony 1.4.13
sensiolabs symfony 1.4.11
sensiolabs symfony *
sensiolabs symfony 1.4.8
sensiolabs symfony 1.4.7
CVE-2012-6431 MEDIUM

Symfony 2.0.x before 2.0.20 does not process URL encoded data consistently within the Routing and Security components, which allows remote attackers to bypass intended URI restrictions via a doubly encoded string.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
sensiolabs symfony 2.0.14
sensiolabs symfony 2.0.6
sensiolabs symfony 2.0.19
sensiolabs symfony 2.0.3
sensiolabs symfony 2.0.15
sensiolabs symfony 2.0.16
sensiolabs symfony 2.0.0
sensiolabs symfony 2.0.9
sensiolabs symfony 2.0.1
sensiolabs symfony 2.0.8
sensiolabs symfony 2.0.4
sensiolabs symfony 2.0.2
sensiolabs symfony 2.0.7
sensiolabs symfony 2.0.17
sensiolabs symfony 2.0.5
sensiolabs symfony 2.0.11
sensiolabs symfony 2.0.12
sensiolabs symfony 2.0.13
sensiolabs symfony 2.0.18
sensiolabs symfony 2.0.10
CVE-2012-6432 MEDIUM

Symfony 2.0.x before 2.0.20, 2.1.x before 2.1.5, and 2.2-dev, when the internal routes configuration is enabled, allows remote attackers to access arbitrary services via vectors involving a URI beginning with a /_internal substring.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
sensiolabs symfony 2.0.14
sensiolabs symfony 2.0.20
sensiolabs symfony 2.0.19
sensiolabs symfony 2.0.3
sensiolabs symfony 2.0.15
sensiolabs symfony 2.1.3
sensiolabs symfony 2.0.16
sensiolabs symfony 2.0.9
sensiolabs symfony 2.2
sensiolabs symfony 2.0.8
sensiolabs symfony 2.0.7
sensiolabs symfony 2.0.12
sensiolabs symfony 2.0.6
sensiolabs symfony 2.0.0
sensiolabs symfony 2.0.1
sensiolabs symfony 2.1.0
sensiolabs symfony 2.0.2
sensiolabs symfony 2.0.4
sensiolabs symfony 2.0.11
sensiolabs symfony 2.0.5
sensiolabs symfony 2.0.17
sensiolabs symfony 2.1.2
sensiolabs symfony 2.0.13
sensiolabs symfony 2.0.18
sensiolabs symfony 2.1.1
sensiolabs symfony 2.0.10
CVE-2013-1348 HIGH

The Yaml::parse function in Symfony 2.0.x before 2.0.22 remote attackers to execute arbitrary PHP code via a PHP file, a different vulnerability than CVE-2013-1397.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-94,

Products Affected

Vendor Product Version
sensiolabs symfony 2.0.6
sensiolabs symfony 2.0.20
sensiolabs symfony 2.0.14
sensiolabs symfony 2.0.19
sensiolabs symfony 2.0.3
sensiolabs symfony 2.0.15
sensiolabs symfony 2.0.16
sensiolabs symfony 2.0.0
sensiolabs symfony 2.0.9
sensiolabs symfony 2.0.1
sensiolabs symfony 2.0.8
sensiolabs symfony 2.0.7
sensiolabs symfony 2.0.2
sensiolabs symfony 2.0.4
sensiolabs symfony 2.0.11
sensiolabs symfony 2.0.17
sensiolabs symfony 2.0.5
sensiolabs symfony 2.0.12
sensiolabs symfony 2.0.13
sensiolabs symfony 2.0.21
sensiolabs symfony 2.0.18
sensiolabs symfony 2.0.10
CVE-2013-1397 HIGH

Symfony 2.0.x before 2.0.22, 2.1.x before 2.1.7, and 2.2.x remote attackers to execute arbitrary PHP code via a serialized PHP object to the (1) Yaml::parse or (2) Yaml\Parser::parse function, a different vulnerability than CVE-2013-1348.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-94,

Products Affected

Vendor Product Version
sensiolabs symfony 2.0.20
sensiolabs symfony 2.0.14
sensiolabs symfony 2.0.19
sensiolabs symfony 2.0.3
sensiolabs symfony 2.2.9
sensiolabs symfony 2.2.11
sensiolabs symfony 2.0.15
sensiolabs symfony 2.2.8
sensiolabs symfony 2.1.3
sensiolabs symfony 2.0.16
sensiolabs symfony 2.0.9
sensiolabs symfony 2.1.4
sensiolabs symfony 2.2.6
sensiolabs symfony 2.2.5
sensiolabs symfony 2.0.8
sensiolabs symfony 2.0.7
sensiolabs symfony 2.2.1
sensiolabs symfony 2.0.12
sensiolabs symfony 2.2.3
sensiolabs symfony 2.2.4
sensiolabs symfony 2.2.0
sensiolabs symfony 2.2.2
sensiolabs symfony 2.0.6
sensiolabs symfony 2.2.10
sensiolabs symfony 2.0.0
sensiolabs symfony 2.1.5
sensiolabs symfony 2.1.6
sensiolabs symfony 2.0.1
sensiolabs symfony 2.1.0
sensiolabs symfony 2.0.2
sensiolabs symfony 2.0.4
sensiolabs symfony 2.0.5
sensiolabs symfony 2.0.17
sensiolabs symfony 2.0.11
sensiolabs symfony 2.1.2
sensiolabs symfony 2.0.21
sensiolabs symfony 2.0.13
sensiolabs symfony 2.0.18
sensiolabs symfony 2.0.10
sensiolabs symfony 2.1.1
CVE-2013-5958 MEDIUM

The Security component in Symfony 2.0.x before 2.0.25, 2.1.x before 2.1.13, 2.2.x before 2.2.9, and 2.3.x before 2.3.6 allows remote attackers to cause a denial of service (CPU consumption) via a long password that triggers an expensive hash computation, as demonstrated by a PBKDF2 computation, a similar issue to CVE-2013-5750.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-399,

Products Affected

Vendor Product Version
sensiolabs symfony 2.0.14
sensiolabs symfony 2.0.20
sensiolabs symfony 2.1.10
sensiolabs symfony 2.0.19
sensiolabs symfony 2.0.15
sensiolabs symfony 2.2.8
sensiolabs symfony 2.1.8
sensiolabs symfony 2.3.4
sensiolabs symfony 2.0.9
sensiolabs symfony 2.1.4
sensiolabs symfony 2.2.6
sensiolabs symfony 2.0.8
sensiolabs symfony 2.0.7
sensiolabs symfony 2.2.1
sensiolabs symfony 2.0.12
sensiolabs symfony 2.0.6
sensiolabs symfony 2.0.24
sensiolabs symfony 2.3.1
sensiolabs symfony 2.1.9
sensiolabs symfony 2.0.1
sensiolabs symfony 2.3.2
sensiolabs symfony 2.1.0
sensiolabs symfony 2.0.5
sensiolabs symfony 2.0.17
sensiolabs symfony 2.1.12
sensiolabs symfony 2.0.13
sensiolabs symfony 2.3.3
sensiolabs symfony 2.0.18
sensiolabs symfony 2.0.3
sensiolabs symfony 2.0.22
sensiolabs symfony 2.1.3
sensiolabs symfony 2.0.16
sensiolabs symfony 2.2
sensiolabs symfony 2.2.5
sensiolabs symfony 2.1.11
sensiolabs symfony 2.2.4
sensiolabs symfony 2.2.3
sensiolabs symfony 2.1.7
sensiolabs symfony 2.2.0
sensiolabs symfony 2.2.2
sensiolabs symfony 2.3.0
sensiolabs symfony 2.3.5
sensiolabs symfony 2.0.23
sensiolabs symfony 2.0.0
sensiolabs symfony 2.1.5
sensiolabs symfony 2.1.6
sensiolabs symfony 2.0.4
sensiolabs symfony 2.0.2
sensiolabs symfony 2.0.11
sensiolabs symfony 2.1.2
sensiolabs symfony 2.0.21
sensiolabs symfony 2.0.10
sensiolabs symfony 2.1.1
CVE-2015-2308 MEDIUM

Eval injection vulnerability in the HttpCache class in HttpKernel in Symfony 2.x before 2.3.27, 2.4.x and 2.5.x before 2.5.11, and 2.6.x before 2.6.6 allows remote attackers to execute arbitrary PHP code via a language="php" attribute of a SCRIPT element.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-94,

Products Affected

Vendor Product Version
sensiolabs symfony 2.0.20
sensiolabs symfony 2.4.1
sensiolabs symfony 2.0.14
sensiolabs symfony 2.0.19
sensiolabs symfony 2.3.22
sensiolabs symfony 2.5.8
sensiolabs symfony 2.2.9
sensiolabs symfony 2.0.15
sensiolabs symfony 2.4.9
sensiolabs symfony 2.5.3
sensiolabs symfony 2.2.8
sensiolabs symfony 2.5.6
sensiolabs symfony 2.0.9
sensiolabs symfony 2.1.4
sensiolabs symfony 2.5.2
sensiolabs symfony 2.2.6
sensiolabs symfony 2.0.8
sensiolabs symfony 2.2.1
sensiolabs symfony 2.0.7
sensiolabs symfony 2.0.12
sensiolabs symfony 2.4.6
sensiolabs symfony 2.6.3
sensiolabs symfony 2.0.6
sensiolabs symfony 2.4.7
sensiolabs symfony 2.6.1
sensiolabs symfony 2.4.8
sensiolabs symfony 2.3.24
sensiolabs symfony 2.0.1
sensiolabs symfony 2.3.19
sensiolabs symfony 2.6.0
sensiolabs symfony 2.1.0
sensiolabs symfony 2.0.17
sensiolabs symfony 2.4.10
sensiolabs symfony 2.0.5
sensiolabs symfony 2.0.13
sensiolabs symfony 2.0.18
sensiolabs symfony 2.6.4
sensiolabs symfony 2.3.21
sensiolabs symfony 2.3.25
sensiolabs symfony 2.3.26
sensiolabs symfony 2.0.3
sensiolabs symfony 2.2.11
sensiolabs symfony 2.4.2
sensiolabs symfony 2.0.22
sensiolabs symfony 2.4.5
sensiolabs symfony 2.1.3
sensiolabs symfony 2.0.16
sensiolabs symfony 2.6.5
sensiolabs symfony 2.2.5
sensiolabs symfony 2.5.10
sensiolabs symfony 2.4.3
sensiolabs symfony 2.2.4
sensiolabs symfony 2.2.3
sensiolabs symfony 2.1.7
sensiolabs symfony 2.5.9
sensiolabs symfony 2.2.0
sensiolabs symfony 2.2.2
sensiolabs symfony 2.2.10
sensiolabs symfony 2.4.4
sensiolabs symfony 2.3.23
sensiolabs symfony 2.0.0
sensiolabs symfony 2.5.4
sensiolabs symfony 2.1.5
sensiolabs symfony 2.3.20
sensiolabs symfony 2.1.6
sensiolabs symfony 2.0.2
sensiolabs symfony 2.0.4
sensiolabs symfony 2.0.11
sensiolabs symfony 2.1.2
sensiolabs symfony 2.0.21
sensiolabs symfony 2.5.5
sensiolabs symfony 2.5.7
sensiolabs symfony 2.5.1
sensiolabs symfony 2.0.10
sensiolabs symfony 2.1.1
CVE-2015-4050 MEDIUM

FragmentListener in the HttpKernel component in Symfony 2.3.19 through 2.3.28, 2.4.9 through 2.4.10, 2.5.4 through 2.5.11, and 2.6.0 through 2.6.7, when ESI or SSI support enabled, does not check if the _controller attribute is set, which allows remote attackers to bypass URL signing and security rules by including (1) no hash or (2) an invalid hash in a request to /_fragment.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-284,

Products Affected

Vendor Product Version
sensiolabs symfony 2.3.25
sensiolabs symfony 2.3.26
sensiolabs symfony 2.3.22
sensiolabs symfony 2.5.8
sensiolabs symfony 2.4.9
sensiolabs symfony 2.5.6
sensiolabs symfony 2.3.28
sensiolabs symfony 2.3.27
sensiolabs symfony 2.6.5
sensiolabs symfony 2.5.10
sensiolabs symfony 2.5.9
sensiolabs symfony 2.6.3
sensiolabs symfony 2.6.6
sensiolabs symfony 2.6.1
sensiolabs symfony 2.3.23
sensiolabs symfony 2.5.4
sensiolabs symfony 2.3.20
sensiolabs symfony 2.3.24
sensiolabs symfony 2.3.19
sensiolabs symfony 2.6.0
sensiolabs symfony 2.4.10
sensiolabs symfony 2.5.5
sensiolabs symfony 2.5.11
sensiolabs symfony 2.6.4
sensiolabs symfony 2.3.21
sensiolabs symfony 2.5.7
sensiolabs symfony 2.6.7
CVE-2015-8124 MEDIUM

Session fixation vulnerability in the "Remember Me" login feature in Symfony 2.3.x before 2.3.35, 2.6.x before 2.6.12, and 2.7.x before 2.7.7 allows remote attackers to hijack web sessions via a session id.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
sensiolabs symfony 2.3.14
sensiolabs symfony 2.3.22
sensiolabs symfony 2.3.30
sensiolabs symfony 2.3.34
sensiolabs symfony 2.3.4
sensiolabs symfony 2.6.10
sensiolabs symfony 2.3.17
sensiolabs symfony 2.3.28
sensiolabs symfony 2.3.27
sensiolabs symfony 2.3.33
sensiolabs symfony 2.3.16
sensiolabs symfony 2.6.3
sensiolabs symfony 2.7.3
sensiolabs symfony 2.3.9
sensiolabs symfony 2.3.1
sensiolabs symfony 2.3.31
sensiolabs symfony 2.6.1
sensiolabs symfony 2.6.9
sensiolabs symfony 2.3.7
sensiolabs symfony 2.3.24
sensiolabs symfony 2.3.19
sensiolabs symfony 2.7.6
sensiolabs symfony 2.3.2
sensiolabs symfony 2.6.0
sensiolabs symfony 2.3.32
sensiolabs symfony 2.6.4
sensiolabs symfony 2.3.3
sensiolabs symfony 2.3.21
sensiolabs symfony 2.6.7
sensiolabs symfony 2.7.1
sensiolabs symfony 2.3.25
sensiolabs symfony 2.3.26
sensiolabs symfony 2.3.6
sensiolabs symfony 2.6.5
sensiolabs symfony 2.3.15
sensiolabs symfony 2.3.29
sensiolabs symfony 2.3.18
sensiolabs symfony 2.7.4
sensiolabs symfony 2.3.13
sensiolabs symfony 2.6.6
sensiolabs symfony 2.3.0
sensiolabs symfony 2.3.8
sensiolabs symfony 2.3.5
sensiolabs symfony 2.7.0
sensiolabs symfony 2.7.5
sensiolabs symfony 2.3.23
sensiolabs symfony 2.3.10
sensiolabs symfony 2.3.11
sensiolabs symfony 2.3.12
sensiolabs symfony 2.3.20
sensiolabs symfony 2.6.11
sensiolabs symfony 2.7.2
sensiolabs symfony 2.6.2
sensiolabs symfony 2.6.8
CVE-2015-8125 HIGH

Symfony 2.3.x before 2.3.35, 2.6.x before 2.6.12, and 2.7.x before 2.7.7 might allow remote attackers to have unspecified impact via a timing attack involving the (1) Symfony/Component/Security/Http/RememberMe/PersistentTokenBasedRememberMeServices or (2) Symfony/Component/Security/Http/Firewall/DigestAuthenticationListener class in the Symfony Security Component, or (3) legacy CSRF implementation from the Symfony/Component/Form/Extension/Csrf/CsrfProvider/DefaultCsrfProvider class in the Symfony Form component.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
sensiolabs symfony 2.3.14
sensiolabs symfony 2.3.22
sensiolabs symfony 2.3.30
sensiolabs symfony 2.3.34
sensiolabs symfony 2.3.4
sensiolabs symfony 2.6.10
sensiolabs symfony 2.3.17
sensiolabs symfony 2.3.28
sensiolabs symfony 2.3.27
sensiolabs symfony 2.3.33
sensiolabs symfony 2.3.16
sensiolabs symfony 2.6.3
sensiolabs symfony 2.7.3
sensiolabs symfony 2.3.9
sensiolabs symfony 2.3.1
sensiolabs symfony 2.6.1
sensiolabs symfony 2.3.31
sensiolabs symfony 2.6.9
sensiolabs symfony 2.3.7
sensiolabs symfony 2.3.19
sensiolabs symfony 2.3.24
sensiolabs symfony 2.7.6
sensiolabs symfony 2.6.0
sensiolabs symfony 2.3.2
sensiolabs symfony 2.3.32
sensiolabs symfony 2.3.3
sensiolabs symfony 2.6.4
sensiolabs symfony 2.3.21
sensiolabs symfony 2.6.7
sensiolabs symfony 2.7.1
sensiolabs symfony 2.3.25
sensiolabs symfony 2.3.26
sensiolabs symfony 2.3.6
sensiolabs symfony 2.6.5
sensiolabs symfony 2.3.15
sensiolabs symfony 2.3.29
sensiolabs symfony 2.3.18
sensiolabs symfony 2.7.4
sensiolabs symfony 2.3.13
sensiolabs symfony 2.6.6
sensiolabs symfony 2.3.0
sensiolabs symfony 2.3.8
sensiolabs symfony 2.7.0
sensiolabs symfony 2.3.5
sensiolabs symfony 2.7.5
sensiolabs symfony 2.3.23
sensiolabs symfony 2.3.10
sensiolabs symfony 2.3.12
sensiolabs symfony 2.3.11
sensiolabs symfony 2.3.20
sensiolabs symfony 2.6.11
sensiolabs symfony 2.7.2
sensiolabs symfony 2.6.2
sensiolabs symfony 2.6.8
CVE-2016-1902 MEDIUM

The nextBytes function in the SecureRandom class in Symfony before 2.3.37, 2.6.x before 2.6.13, and 2.7.x before 2.7.9 does not properly generate random numbers when used with PHP 5.x without the paragonie/random_compat library and the openssl_random_pseudo_bytes function fails, which makes it easier for attackers to defeat cryptographic protection mechanisms via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-310,

Products Affected

Vendor Product Version
sensiolabs symfony 2.6.10
sensiolabs symfony 2.6.5
sensiolabs symfony *
sensiolabs symfony 2.7.8
sensiolabs symfony 2.7.7
sensiolabs symfony 2.7.4
sensiolabs symfony 2.6.3
debian debian_linux 8.0
sensiolabs symfony 2.7.3
sensiolabs symfony 2.6.6
sensiolabs symfony 2.7.0
sensiolabs symfony 2.6.1
sensiolabs symfony 2.6.9
sensiolabs symfony 2.7.5
sensiolabs symfony 2.7.6
sensiolabs symfony 2.7.2
sensiolabs symfony 2.6.0
sensiolabs symfony 2.6.11
sensiolabs symfony 2.6.12
sensiolabs symfony 2.6.2
sensiolabs symfony 2.6.4
sensiolabs symfony 2.6.7
sensiolabs symfony 2.7.1
sensiolabs symfony 2.6.8
CVE-2016-2403 HIGH

Symfony before 2.8.6 and 3.x before 3.0.6 allows remote attackers to bypass authentication by logging in with an empty password and valid username, which triggers an unauthenticated bind.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-287,

Products Affected

Vendor Product Version
sensiolabs symfony 3.0.3
sensiolabs symfony 2.8.2
sensiolabs symfony 3.0.1
sensiolabs symfony 2.8.5
sensiolabs symfony 2.8.4
sensiolabs symfony 3.0.0
sensiolabs symfony 2.8.0
sensiolabs symfony 3.0.2
sensiolabs symfony 2.8.3
sensiolabs symfony 3.0.5
sensiolabs symfony 2.8.1
sensiolabs symfony 3.0.4
CVE-2016-4423 MEDIUM

The attemptAuthentication function in Component/Security/Http/Firewall/UsernamePasswordFormAuthenticationListener.php in Symfony before 2.3.41, 2.7.x before 2.7.13, 2.8.x before 2.8.6, and 3.0.x before 3.0.6 does not limit the length of a username stored in a session, which allows remote attackers to cause a denial of service (session storage consumption) via a series of authentication attempts with long, non-existent usernames.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-399,

Products Affected

Vendor Product Version
sensiolabs symfony 3.0.3
sensiolabs symfony 2.8.2
sensiolabs symfony 3.0.1
sensiolabs symfony 2.7.11
sensiolabs symfony 2.7.12
sensiolabs symfony 2.7.9
sensiolabs symfony *
sensiolabs symfony 2.7.7
sensiolabs symfony 2.7.8
sensiolabs symfony 2.8.1
sensiolabs symfony 2.7.4
sensiolabs symfony 3.0.4
sensiolabs symfony 2.7.3
debian debian_linux 8.0
sensiolabs symfony 2.7.0
sensiolabs symfony 2.7.5
sensiolabs symfony 2.8.5
sensiolabs symfony 2.8.4
sensiolabs symfony 3.0.0
sensiolabs symfony 2.8.0
sensiolabs symfony 2.7.2
sensiolabs symfony 3.0.2
sensiolabs symfony 2.7.6
sensiolabs symfony 2.8.3
sensiolabs symfony 3.0.5
sensiolabs symfony 2.7.10
sensiolabs symfony 2.7.1
CVE-2017-11365 HIGH

Certain Symfony products are affected by: Incorrect Access Control. This affects Symfony 2.7.30 and Symfony 2.8.23 and Symfony 3.2.10 and Symfony 3.3.3. The type of exploitation is: remote. The component is: Password validator.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-284,

Products Affected

Vendor Product Version
sensiolabs symfony 2.7.30
sensiolabs symfony 2.8.23
sensiolabs symfony 3.3.3
sensiolabs symfony 3.2.10
CVE-2017-16652 MEDIUM

An issue was discovered in Symfony 2.7.x before 2.7.38, 2.8.x before 2.8.31, 3.2.x before 3.2.14, and 3.3.x before 3.3.13. DefaultAuthenticationSuccessHandler or DefaultAuthenticationFailureHandler takes the content of the _target_path parameter and generates a redirect response, but no check is performed on the path, which could be an absolute URL to an external domain. This Open redirect vulnerability can be exploited for example to mount effective phishing attacks.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-601,

Products Affected

Vendor Product Version
sensiolabs symfony *
debian debian_linux 8.0
CVE-2017-16653 MEDIUM

An issue was discovered in Symfony before 2.7.38, 2.8.31, 3.2.14, 3.3.13, 3.4-BETA5, and 4.0-BETA5. The current implementation of CSRF protection in Symfony (Version >=2) does not use different tokens for HTTP and HTTPS; therefore the token is subject to MITM attacks on HTTP and can then be used in an HTTPS context to do CSRF attacks.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
sensiolabs symfony *
debian debian_linux 9.0
CVE-2017-16654 MEDIUM

An issue was discovered in Symfony before 2.7.38, 2.8.31, 3.2.14, 3.3.13, 3.4-BETA5, and 4.0-BETA5. The Intl component includes various bundle readers that are used to read resource bundles from the local filesystem. The read() methods of these classes use a path and a locale to determine the language bundle to retrieve. The locale argument value is commonly retrieved from untrusted user input (like a URL parameter). An attacker can use this argument to navigate to arbitrary directories via the dot-dot-slash attack, aka Directory Traversal.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-22,

Products Affected

Vendor Product Version
sensiolabs symfony *
debian debian_linux 9.0
debian debian_linux 8.0
CVE-2017-16790 MEDIUM

An issue was discovered in Symfony before 2.7.38, 2.8.31, 3.2.14, 3.3.13, 3.4-BETA5, and 4.0-BETA5. When a form is submitted by the user, the request handler classes of the Form component merge POST data and uploaded files data into one array. This big array forms the data that are then bound to the form. At this stage there is no difference anymore between submitted POST data and uploaded files. A user can send a crafted HTTP request where the value of a "FileType" is sent as normal POST data that could be interpreted as a local file path on the server-side (for example, "file:///etc/passwd"). If the application did not perform any additional checks about the value submitted to the "FileType", the contents of the given file on the server could have been exposed to the attacker.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
sensiolabs symfony *
debian debian_linux 9.0
CVE-2017-18343 MEDIUM

The debug handler in Symfony before v2.7.33, 2.8.x before v2.8.26, 3.x before v3.2.13, and 3.3.x before v3.3.6 has XSS via an array key during exception pretty printing in ExceptionHandler.php, as demonstrated by a /_debugbar/open?op=get URI. NOTE: the vendor's position is that this is not a vulnerability because the debug tools are not intended for production use. NOTE: the Symfony Debug component is used by Laravel Debugbar

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
sensiolabs symfony *
CVE-2018-11385 MEDIUM

An issue was discovered in the Security component in Symfony 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x before 4.0.11. A session fixation vulnerability within the "Guard" login feature may allow an attacker to impersonate a victim towards the web application if the session id value was previously known to the attacker.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-384,

Products Affected

Vendor Product Version
sensiolabs symfony *
fedoraproject fedora 28
debian debian_linux 9.0
debian debian_linux 8.0
CVE-2018-11386 MEDIUM

An issue was discovered in the HttpFoundation component in Symfony 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x before 4.0.11. The PDOSessionHandler class allows storing sessions on a PDO connection. Under some configurations and with a well-crafted payload, it was possible to do a denial of service on a Symfony application without too much resources.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-613,

Products Affected

Vendor Product Version
sensiolabs symfony *
debian debian_linux 9.0
CVE-2018-11406 MEDIUM

An issue was discovered in the Security component in Symfony 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x before 4.0.11. By default, a user's session is invalidated when the user is logged out. This behavior can be disabled through the invalidate_session option. In this case, CSRF tokens were not erased during logout which allowed for CSRF token fixation.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-352,

Products Affected

Vendor Product Version
sensiolabs symfony *
debian debian_linux 9.0
CVE-2018-11407 HIGH

An issue was discovered in the Ldap component in Symfony 2.8.x before 2.8.37, 3.3.x before 3.3.17, 3.4.x before 3.4.7, and 4.0.x before 4.0.7. It allows remote attackers to bypass authentication by logging in with a "null" password and valid username, which triggers an unauthenticated bind. NOTE: this issue exists because of an incomplete fix for CVE-2016-2403.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-287,

Products Affected

Vendor Product Version
sensiolabs symfony *
CVE-2018-11408 MEDIUM

The security handlers in the Security component in Symfony in 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x before 4.0.11 have an Open redirect vulnerability when security.http_utils is inlined by a container. NOTE: this issue exists because of an incomplete fix for CVE-2017-16652.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-601,

Products Affected

Vendor Product Version
sensiolabs symfony *
debian debian_linux 8.0
CVE-2018-12040 MEDIUM

Reflected Cross-site scripting (XSS) vulnerability in the web profiler in SensioLabs Symfony 3.3.6 allows remote attackers to inject arbitrary web script or HTML via the "file" parameter, aka an _profiler/open?file= URI. NOTE: The vendor states "The XSS ... is in the web profiler, a tool that should never be deployed in production (so, we don't handle those issues as security issues).

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
sensiolabs symfony 3.3.6
CVE-2018-14773 MEDIUM

An issue was discovered in Http Foundation in Symfony 2.7.0 through 2.7.48, 2.8.0 through 2.8.43, 3.3.0 through 3.3.17, 3.4.0 through 3.4.13, 4.0.0 through 4.0.13, and 4.1.0 through 4.1.2. It arises from support for a (legacy) IIS header that lets users override the path in the request URL via the X-Original-URL or X-Rewrite-URL HTTP request header. These headers are designed for IIS support, but it's not verified that the server is in fact running IIS, which means anybody who can send these requests to an application can trigger this. This affects \Symfony\Component\HttpFoundation\Request::prepareRequestUri() where X-Original-URL and X_REWRITE_URL are both used. The fix drops support for these methods so that they cannot be used as attack vectors such as web cache poisoning.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 6.5 MEDIUM CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N 2.8 3.6

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
sensiolabs symfony *
drupal drupal *
debian debian_linux 9.0
debian debian_linux 8.0
CVE-2018-14774 MEDIUM

An issue was discovered in HttpKernel in Symfony 2.7.0 through 2.7.48, 2.8.0 through 2.8.43, 3.3.0 through 3.3.17, 3.4.0 through 3.4.13, 4.0.0 through 4.0.13, and 4.1.0 through 4.1.2. When using HttpCache, the values of the X-Forwarded-Host headers are implicitly set as trusted while this should be forbidden, leading to potential host header injection.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
sensiolabs symfony *
CVE-2018-19789 MEDIUM

An issue was discovered in Symfony 2.7.x before 2.7.50, 2.8.x before 2.8.49, 3.x before 3.4.20, 4.0.x before 4.0.15, 4.1.x before 4.1.9, and 4.2.x before 4.2.1. When using the scalar type hint `string` in a setter method (e.g. `setName(string $name)`) of a class that's the `data_class` of a form, and when a file upload is submitted to the corresponding field instead of a normal text input, then `UploadedFile::__toString()` is called which will then return and disclose the path of the uploaded file. If combined with a local file inclusion issue in certain circumstances this could escalate it to a Remote Code Execution.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-434,

Products Affected

Vendor Product Version
sensiolabs symfony *
debian debian_linux 8.0
CVE-2018-19790 MEDIUM

An open redirect was discovered in Symfony 2.7.x before 2.7.50, 2.8.x before 2.8.49, 3.x before 3.4.20, 4.0.x before 4.0.15, 4.1.x before 4.1.9 and 4.2.x before 4.2.1. By using backslashes in the `_failure_path` input field of login forms, an attacker can work around the redirection target restrictions and effectively redirect the user to any domain after login.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-601,

Products Affected

Vendor Product Version
sensiolabs symfony *
fedoraproject fedora 28
debian debian_linux 8.0
CVE-2019-10909 LOW

In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, validation messages are not escaped, which can lead to XSS when user input is included. This is related to symfony/framework-bundle.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 5.4 MEDIUM CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N 2.3 2.7

CVSS 2.0

Severity: LOW

Problem Type: CWE-79,

Products Affected

Vendor Product Version
sensiolabs symfony *
drupal drupal *
CVE-2019-10910 HIGH

In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, when service ids allow user input, this could allow for SQL Injection and remote code execution. This is related to symfony/dependency-injection.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 3.9 5.9

CVSS 2.0

Severity: HIGH

Problem Type: CWE-89,

Products Affected

Vendor Product Version
sensiolabs symfony *
drupal drupal *
CVE-2019-10911 MEDIUM

In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, a vulnerability would allow an attacker to authenticate as a privileged user on sites with user registration and remember me login functionality enabled. This is related to symfony/security.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 7.5 HIGH CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H 1.6 5.9

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-287,

Products Affected

Vendor Product Version
sensiolabs symfony *
drupal drupal *
CVE-2019-10912 MEDIUM

In Symfony before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, it is possible to cache objects that may contain bad user input. On serialization or unserialization, this could result in the deletion of files that the current user has access to. This is related to symfony/cache and symfony/phpunit-bridge.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-502,

Products Affected

Vendor Product Version
sensiolabs symfony *
CVE-2019-10913 HIGH

In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, HTTP Methods provided as verbs or using the override header may be treated as trusted input, but they are not validated, possibly causing SQL injection or XSS. This is related to symfony/http-foundation.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-79,CWE-89,

Products Affected

Vendor Product Version
sensiolabs symfony *