GHSA-g4m9-5hpf-hx72
Firewall configured with unanimous strategy was not actually unanimous in Symfony
Quick fix
GHSA-g4m9-5hpf-hx72 — symfony/security: upgrade to the fixed version with the command below.
composer require symfony/security:^4.4.7Details
Description -----------
On Symfony before 4.4.0, when a `Firewall` checks an access control rule (using the unanimous strategy), it iterates over all rule attributes and grant access only if *all* calls to the `accessDecisionManager` decide to grant access.
As of Symfony 4.4.0, a bug was introduced that prevents the check of attributes as soon as `accessDecisionManager` decide to grant access on one attribute.
Resolution ----------
The `accessDecisionManager` is now called with all attributes at once, allowing the unanimous strategy being applied on each attribute.
The patch for this issue is available [here](https://github.com/symfony/symfony/commit/c935e4a3fba6cc2ab463a6ca382858068d63cebf) for the 4.4 branch.
Credits -------
I would like to thank Antonio J. García Lagar for reporting & Robin Chalas for fixing the issue.
Are you affected?
Enter the version of the package you're using.
Affected packages
4.4.0Fixed in: 4.4.7composer require symfony/security:^4.4.75.0.0Fixed in: 5.0.7composer require symfony/security:^5.0.74.4.0Fixed in: 4.4.7composer require symfony/security-http:^4.4.75.0.0Fixed in: 5.0.7composer require symfony/security-http:^5.0.74.4.0Fixed in: 4.4.7composer require symfony/symfony:^4.4.75.0.0Fixed in: 5.0.7composer require symfony/symfony:^5.0.7References
- https://github.com/symfony/symfony/security/advisories/GHSA-g4m9-5hpf-hx72[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2020-5275[ADVISORY]
- https://github.com/symfony/symfony/commit/c935e4a3fba6cc2ab463a6ca382858068d63cebf[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/security-http/CVE-2020-5275.yaml[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/security/CVE-2020-5275.yaml[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/symfony/CVE-2020-5275.yaml[WEB]
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/C36JLPHUPKDFAX6D5WYFC4ALO2K7RDUQ[WEB]
- https://symfony.com/cve-2020-5275[WEB]