CRITICAL9.8
GHSA-79gr-58r3-pwm3
Symfony Unsafe Cache Serialization Could Enable RCE
Quick fix
GHSA-79gr-58r3-pwm3 — symfony/cache: upgrade to the fixed version with the command below.
composer require symfony/cache:^3.4.35Details
An issue was discovered in Symfony 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4.3.7. Serializing certain cache adapter interfaces could result in remote code injection. This is related to symfony/cache.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/symfony/cache
Introduced in:
3.1.0Fixed in: 3.4.35Fix
composer require symfony/cache:^3.4.35Packagist/symfony/cache
Introduced in:
4.0.0Fixed in: 4.2.12Fix
composer require symfony/cache:^4.2.12Packagist/symfony/symfony
Introduced in:
3.1.0Fixed in: 3.4.35Fix
composer require symfony/symfony:^3.4.35Packagist/symfony/symfony
Introduced in:
4.0.0Fixed in: 4.2.12Fix
composer require symfony/symfony:^4.2.12Packagist/symfony/symfony
Introduced in:
4.3.0Fixed in: 4.3.8Fix
composer require symfony/symfony:^4.3.8References
- https://nvd.nist.gov/vuln/detail/CVE-2019-18889[ADVISORY]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/cache/CVE-2019-18889.yaml[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/symfony/CVE-2019-18889.yaml[WEB]
- https://github.com/symfony/symfony/releases/tag/v4.3.8[WEB]
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UED22BOXTL2SSFMGYKA64ZFHGLLJG3EA[WEB]
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UED22BOXTL2SSFMGYKA64ZFHGLLJG3EA[WEB]
- https://symfony.com/blog/cve-2019-18889-forbid-serializing-abstractadapter-and-tagawareadapter-instances[WEB]
- https://symfony.com/blog/symfony-4-3-8-released[WEB]
- https://symfony.com/cve-2019-18889[WEB]