MEDIUM6.1
GHSA-7hwc-2cq4-6x2w
Symfony Open Redirect
Quick fix
GHSA-7hwc-2cq4-6x2w — symfony/symfony: upgrade to the fixed version with the command below.
composer require symfony/symfony:^2.7.48Details
The security handlers in the Security component in Symfony in 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x before 4.0.11 have an Open redirect vulnerability when security.http_utils is inlined by a container. NOTE: this issue exists because of an incomplete fix for CVE-2017-16652.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/symfony/symfony
Introduced in:
2.7.0Fixed in: 2.7.48Fix
composer require symfony/symfony:^2.7.48Packagist/symfony/symfony
Introduced in:
2.8.0Fixed in: 2.8.41Fix
composer require symfony/symfony:^2.8.41Packagist/symfony/symfony
Introduced in:
3.3.0Fixed in: 3.3.17Fix
composer require symfony/symfony:^3.3.17Packagist/symfony/symfony
Introduced in:
3.4.0Fixed in: 3.4.11Fix
composer require symfony/symfony:^3.4.11Packagist/symfony/symfony
Introduced in:
4.0.0Fixed in: 4.0.11Fix
composer require symfony/symfony:^4.0.11Packagist/symfony/security-bundle
Introduced in:
2.7.0Fixed in: 2.7.48Fix
composer require symfony/security-bundle:^2.7.48Packagist/symfony/security-bundle
Introduced in:
2.8.0Fixed in: 2.8.41Fix
composer require symfony/security-bundle:^2.8.41Packagist/symfony/security-bundle
Introduced in:
3.3.0Fixed in: 3.3.17Fix
composer require symfony/security-bundle:^3.3.17Packagist/symfony/security-bundle
Introduced in:
3.4.0Fixed in: 3.4.11Fix
composer require symfony/security-bundle:^3.4.11Packagist/symfony/security-bundle
Introduced in:
4.0.0Fixed in: 4.0.11Fix
composer require symfony/security-bundle:^4.0.11References
- https://nvd.nist.gov/vuln/detail/CVE-2018-11408[ADVISORY]
- https://github.com/symfony/symfony/commit/b20e83562e32c56f8d9b8296ab07b0e4c0a54db8[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/security-bundle/CVE-2018-11408.yaml[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/symfony/CVE-2018-11408.yaml[WEB]
- https://github.com/symfony/symfony[PACKAGE]
- https://lists.debian.org/debian-lts-announce/2019/03/msg00009.html[WEB]
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/G4XNBMFW33H47O5TZGA7JYCVLDBCXAJV[WEB]
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UBQK7JDXIELADIPGZIOUCZKMAJM5LSBW[WEB]
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WU5N2TZFNGXDGMXMPP7LZCWTFLENF6WH[WEB]
- https://symfony.com/blog/cve-2018-11408-open-redirect-vulnerability-on-security-handlers[WEB]
- https://symfony.com/cve-2018-11408[WEB]