VDB
Sign up
HIGH7.3

GHSA-3rg7-wf37-54rm

Symfony's incorrect parsing of PATH_INFO can lead to limited authorization bypass

Quick fix

GHSA-3rg7-wf37-54rm — symfony/http-foundation: upgrade to the fixed version with the command below.

composer require symfony/http-foundation:^5.4.50

Details

### Description

The `Request` class improperly interprets some `PATH_INFO` in a way that leads to representing some URLs with a path that doesn't start with a `/`. This can allow bypassing some access control rules that are built with this `/`-prefix assumption.

### Resolution

The `Request` class now ensures that URL paths always start with a `/`.

The patch for this issue is available [here](https://github.com/symfony/symfony/commit/9962b91b12bb791322fa73836b350836b6db7cac) for branch 5.4.

### Credits

We would like to thank Andrew Atkinson for discovering the issue, Chris Smith for reporting it and Nicolas Grekas for providing the fix.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/symfony/http-foundation
Introduced in: 0Fixed in: 5.4.50
Fixcomposer require symfony/http-foundation:^5.4.50
Packagist/symfony/http-foundation
Introduced in: 6.0.0Fixed in: 6.4.29
Fixcomposer require symfony/http-foundation:^6.4.29
Packagist/symfony/http-foundation
Introduced in: 7.0.0Fixed in: 7.3.7
Fixcomposer require symfony/http-foundation:^7.3.7
Packagist/symfony/symfony
Introduced in: 2.0.0Fixed in: 5.4.50
Fixcomposer require symfony/symfony:^5.4.50
Packagist/symfony/symfony
Introduced in: 6.0.0Fixed in: 6.4.29
Fixcomposer require symfony/symfony:^6.4.29
Packagist/symfony/symfony
Introduced in: 7.0.0Fixed in: 7.3.7
Fixcomposer require symfony/symfony:^7.3.7

References