GHSA-mcx4-f5f5-4859
Prevent cache poisoning via a Response Content-Type header in Symfony
Quick fix
GHSA-mcx4-f5f5-4859 — symfony/http-foundation: upgrade to the fixed version with the command below.
composer require symfony/http-foundation:^4.4.7Details
Description -----------
When a `Response` does not contain a `Content-Type` header, Symfony falls back to the format defined in the `Accept` header of the request, leading to a possible mismatch between the response's content and `Content-Type` header. When the response is cached, this can lead to a corrupted cache where the cached format is not the right one.
Resolution ----------
Symfony does not use the `Accept` header anymore to guess the `Content-Type`.
The patch for this issue is available [here](https://github.com/symfony/symfony/commit/dca343442e6a954f96a2609e7b4e9c21ed6d74e6) for the 4.4 branch.
Credits -------
I would like to thank Xavier Lacot from JoliCode for reporting & Yonel Ceruto and Tobias Schultze for fixing the issue.
Are you affected?
Enter the version of the package you're using.
Affected packages
4.4.0Fixed in: 4.4.7composer require symfony/http-foundation:^4.4.75.0.0Fixed in: 5.0.7composer require symfony/http-foundation:^5.0.74.4.0Fixed in: 4.4.7composer require symfony/symfony:^4.4.75.0.0Fixed in: 5.0.7composer require symfony/symfony:^5.0.7References
- https://github.com/symfony/symfony/security/advisories/GHSA-mcx4-f5f5-4859[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2020-5255[ADVISORY]
- https://github.com/symfony/symfony/commit/dca343442e6a954f96a2609e7b4e9c21ed6d74e6[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/http-foundation/CVE-2020-5255.yaml[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/symfony/CVE-2020-5255.yaml[WEB]
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/C36JLPHUPKDFAX6D5WYFC4ALO2K7RDUQ[WEB]
- https://symfony.com/blog/cve-2020-5255-prevent-cache-poisoning-via-a-response-content-type-header[WEB]
- https://symfony.com/cve-2020-5255[WEB]