VDB
Sign up
CRITICAL9.8

GHSA-79gr-58r3-pwm3

Symfony Unsafe Cache Serialization Could Enable RCE

Quick fix

GHSA-79gr-58r3-pwm3 — symfony/cache: upgrade to the fixed version with the command below.

composer require symfony/cache:^3.4.35

Details

An issue was discovered in Symfony 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4.3.7. Serializing certain cache adapter interfaces could result in remote code injection. This is related to symfony/cache.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/symfony/cache
Introduced in: 3.1.0Fixed in: 3.4.35
Fixcomposer require symfony/cache:^3.4.35
Packagist/symfony/cache
Introduced in: 4.0.0Fixed in: 4.2.12
Fixcomposer require symfony/cache:^4.2.12
Packagist/symfony/cache
Introduced in: 4.3.0Fixed in: 4.3.8
Fixcomposer require symfony/cache:^4.3.8
Packagist/symfony/symfony
Introduced in: 3.1.0Fixed in: 3.4.35
Fixcomposer require symfony/symfony:^3.4.35
Packagist/symfony/symfony
Introduced in: 4.0.0Fixed in: 4.2.12
Fixcomposer require symfony/symfony:^4.2.12
Packagist/symfony/symfony
Introduced in: 4.3.0Fixed in: 4.3.8
Fixcomposer require symfony/symfony:^4.3.8

References