MEDIUM5.4
GHSA-g996-q5r8-w7g2
Symfony Cross-site Scripting (XSS) vulnerability
Quick fix
GHSA-g996-q5r8-w7g2 — symfony/symfony: upgrade to the fixed version with the command below.
composer require symfony/symfony:^2.7.51Details
In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, validation messages are not escaped, which can lead to XSS when user input is included. This is related to symfony/framework-bundle.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/symfony/symfony
Introduced in:
2.7.0Fixed in: 2.7.51Fix
composer require symfony/symfony:^2.7.51Packagist/symfony/symfony
Introduced in:
2.8.0Fixed in: 2.8.50Fix
composer require symfony/symfony:^2.8.50Packagist/symfony/symfony
Introduced in:
3.0.0Fixed in: 3.4.26Fix
composer require symfony/symfony:^3.4.26Packagist/symfony/symfony
Introduced in:
4.0.0Fixed in: 4.1.12Fix
composer require symfony/symfony:^4.1.12Packagist/symfony/symfony
Introduced in:
4.2.0Fixed in: 4.2.7Fix
composer require symfony/symfony:^4.2.7Packagist/symfony/framework-bundle
Introduced in:
2.7.0Fixed in: 2.7.51Fix
composer require symfony/framework-bundle:^2.7.51Packagist/symfony/framework-bundle
Introduced in:
2.8.0Fixed in: 2.8.50Fix
composer require symfony/framework-bundle:^2.8.50Packagist/symfony/framework-bundle
Introduced in:
3.0.0Fixed in: 3.4.26Fix
composer require symfony/framework-bundle:^3.4.26Packagist/symfony/framework-bundle
Introduced in:
4.0.0Fixed in: 4.1.12Fix
composer require symfony/framework-bundle:^4.1.12Packagist/symfony/framework-bundle
Introduced in:
4.2.0Fixed in: 4.2.7Fix
composer require symfony/framework-bundle:^4.2.7Packagist/drupal/drupal
Introduced in:
8.0.0Fixed in: 8.5.15Fix
composer require drupal/drupal:^8.5.15Packagist/drupal/drupal
Introduced in:
8.6.0Fixed in: 8.6.15Fix
composer require drupal/drupal:^8.6.15References
- https://nvd.nist.gov/vuln/detail/CVE-2019-10909[ADVISORY]
- https://github.com/symfony/symfony/commit/ab4d05358c3d0dd1a36fc8c306829f68e3dd84e2[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/drupal/core/CVE-2019-10909.yaml[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/drupal/drupal/CVE-2019-10909.yaml[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/framework-bundle/CVE-2019-10909.yaml[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/symfony/CVE-2019-10909.yaml[WEB]
- https://symfony.com/blog/cve-2019-10909-escape-validation-messages-in-the-php-templating-engine[WEB]
- https://symfony.com/cve-2019-10909[WEB]
- https://www.drupal.org/sa-core-2019-005[WEB]
- https://www.synology.com/security/advisory/Synology_SA_19_19[WEB]