VDB
Sign up
HIGH

GHSA-2r5h-6r7v-5m7c

Symphony Vulnerable to PHP Code Injection via YAML Parsing

Quick fix

GHSA-2r5h-6r7v-5m7c — symfony/symfony: upgrade to the fixed version with the command below.

composer require symfony/symfony:^2.0.22

Details

The `Yaml::parse` function in Symfony 2.0.x before 2.0.22 remote attackers to execute arbitrary PHP code via a PHP file, a different vulnerability than CVE-2013-1397.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/symfony/symfony
Introduced in: 2.0.0Fixed in: 2.0.22
Fixcomposer require symfony/symfony:^2.0.22
Packagist/symfony/yaml
Introduced in: 2.0.0Fixed in: 2.0.22
Fixcomposer require symfony/yaml:^2.0.22

References