MEDIUM6.1
GHSA-89r2-5g34-2g47
Symfony Open Redirect
Quick fix
GHSA-89r2-5g34-2g47 — symfony/security-http: upgrade to the fixed version with the command below.
composer require symfony/security-http:^2.7.50Details
An open redirect was discovered in Symfony 2.7.x before 2.7.50, 2.8.x before 2.8.49, 3.x before 3.4.20, 4.0.x before 4.0.15, 4.1.x before 4.1.9 and 4.2.x before 4.2.1. By using backslashes in the `_failure_path` input field of login forms, an attacker can work around the redirection target restrictions and effectively redirect the user to any domain after login.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/symfony/security-http
Introduced in:
2.7.38Fixed in: 2.7.50Fix
composer require symfony/security-http:^2.7.50Packagist/symfony/security-http
Introduced in:
2.8.0Fixed in: 2.8.49Fix
composer require symfony/security-http:^2.8.49Packagist/symfony/security-http
Introduced in:
3.0.0Fixed in: 3.4.20Fix
composer require symfony/security-http:^3.4.20Packagist/symfony/security-http
Introduced in:
4.0.0Fixed in: 4.0.15Fix
composer require symfony/security-http:^4.0.15Packagist/symfony/security-http
Introduced in:
4.1.0Fixed in: 4.1.9Fix
composer require symfony/security-http:^4.1.9Packagist/symfony/security-http
Introduced in:
4.2.0Fixed in: 4.2.1Fix
composer require symfony/security-http:^4.2.1Packagist/symfony/security
Introduced in:
2.7.38Fixed in: 2.7.50Fix
composer require symfony/security:^2.7.50Packagist/symfony/security
Introduced in:
2.8.0Fixed in: 2.8.49Fix
composer require symfony/security:^2.8.49Packagist/symfony/security
Introduced in:
3.0.0Fixed in: 3.4.19Fix
composer require symfony/security:^3.4.19Packagist/symfony/security
Introduced in:
4.0.0Fixed in: 4.0.15Fix
composer require symfony/security:^4.0.15Packagist/symfony/security
Introduced in:
4.1.0Fixed in: 4.1.9Fix
composer require symfony/security:^4.1.9Packagist/symfony/security
Introduced in:
4.2.0Fixed in: 4.2.1Fix
composer require symfony/security:^4.2.1Packagist/symfony/symfony
Introduced in:
2.7.38Fixed in: 2.7.50Fix
composer require symfony/symfony:^2.7.50Packagist/symfony/symfony
Introduced in:
2.8.0Fixed in: 2.8.49Fix
composer require symfony/symfony:^2.8.49Packagist/symfony/symfony
Introduced in:
3.0.0Fixed in: 3.4.20Fix
composer require symfony/symfony:^3.4.20Packagist/symfony/symfony
Introduced in:
4.0.0Fixed in: 4.0.15Fix
composer require symfony/symfony:^4.0.15Packagist/symfony/symfony
Introduced in:
4.1.0Fixed in: 4.1.9Fix
composer require symfony/symfony:^4.1.9References
- https://nvd.nist.gov/vuln/detail/CVE-2018-19790[ADVISORY]
- https://github.com/symfony/symfony/commit/99a0cec0a6be39ce5ef38386e57339603b33ee5b[WEB]
- https://www.debian.org/security/2019/dsa-4441[WEB]
- https://web.archive.org/web/20200227095826/http://www.securityfocus.com/bid/106249[WEB]
- https://symfony.com/cve-2018-19790[WEB]
- https://symfony.com/blog/cve-2018-19790-open-redirect-vulnerability-when-using-security-http[WEB]
- https://seclists.org/bugtraq/2019/May/21[WEB]
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OA4WVFN5FYPIXAPLWZI6N425JHHDSWAZ[WEB]
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JZMRJ7VTHCY5AZK24G4QGX36RLUDTDKE[WEB]
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4TD3E7FZIXLVFG3SMFJPDEKPZ26TJOW7[WEB]
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OA4WVFN5FYPIXAPLWZI6N425JHHDSWAZ[WEB]
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JZMRJ7VTHCY5AZK24G4QGX36RLUDTDKE[WEB]
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4TD3E7FZIXLVFG3SMFJPDEKPZ26TJOW7[WEB]
- https://lists.debian.org/debian-lts-announce/2019/03/msg00009.html[WEB]
- https://github.com/symfony/symfony[PACKAGE]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/symfony/CVE-2018-19790.yaml[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/security/CVE-2018-19790.yaml[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/security-http/CVE-2018-19790.yaml[WEB]
- http://www.securityfocus.com/bid/106249[WEB]