GHSA-h7vf-5wrv-9fhv
Symfony storing cookie headers in HttpCache
Quick fix
GHSA-h7vf-5wrv-9fhv — symfony/http-kernel: upgrade to the fixed version with the command below.
composer require symfony/http-kernel:^4.4.50Details
Description -----------
The Symfony HTTP cache system acts as a reverse proxy: it caches HTTP responses (including headers) and returns them to clients.
In a recent `AbstractSessionListener` change, the response might now contain a `Set-Cookie` header. If the Symfony HTTP cache system is enabled, this header might be stored and returned to some other clients. An attacker can use this vulnerability to retrieve the victim's session.
Resolution ----------
The `HttpStore` constructor now takes a parameter containing a list of private headers that are removed from the HTTP response headers. The default value for this parameter is `Set-Cookie`, but it can be overridden or extended by the application.
The patch for this issue is available [here](https://github.com/symfony/symfony/commit/d2f6322af9444ac5cd1ef3ac6f280dbef7f9d1fb) for branch 4.4.
Credits -------
We would like to thank Soner Sayakci for reporting the issue and Nicolas Grekas for fixing it.
Are you affected?
Enter the version of the package you're using.
Affected packages
2.0.0Fixed in: 4.4.50composer require symfony/http-kernel:^4.4.505.0.0Fixed in: 5.4.20composer require symfony/http-kernel:^5.4.206.0.0Fixed in: 6.0.20composer require symfony/http-kernel:^6.0.206.1.0Fixed in: 6.1.12composer require symfony/http-kernel:^6.1.126.2.0Fixed in: 6.2.6composer require symfony/http-kernel:^6.2.62.0.0Fixed in: 4.4.50composer require symfony/symfony:^4.4.505.0.0Fixed in: 5.4.20composer require symfony/symfony:^5.4.206.0.0Fixed in: 6.0.20composer require symfony/symfony:^6.0.206.1.0Fixed in: 6.1.12composer require symfony/symfony:^6.1.126.2.0Fixed in: 6.2.6composer require symfony/symfony:^6.2.6References
- https://github.com/symfony/symfony/security/advisories/GHSA-h7vf-5wrv-9fhv[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2022-24894[ADVISORY]
- https://github.com/symfony/symfony/commit/d2f6322af9444ac5cd1ef3ac6f280dbef7f9d1fb[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/http-kernel/CVE-2022-24894.yaml[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/symfony/CVE-2022-24894.yaml[WEB]
- https://github.com/symfony/symfony[PACKAGE]
- https://lists.debian.org/debian-lts-announce/2023/07/msg00014.html[WEB]
- https://symfony.com/cve-2022-24894[WEB]