VDB
Sign up
LOW2.6

GHSA-mcx4-f5f5-4859

Prevent cache poisoning via a Response Content-Type header in Symfony

Quick fix

GHSA-mcx4-f5f5-4859 — symfony/http-foundation: upgrade to the fixed version with the command below.

composer require symfony/http-foundation:^4.4.7

Details

Description -----------

When a `Response` does not contain a `Content-Type` header, Symfony falls back to the format defined in the `Accept` header of the request, leading to a possible mismatch between the response's content and `Content-Type` header. When the response is cached, this can lead to a corrupted cache where the cached format is not the right one.

Resolution ----------

Symfony does not use the `Accept` header anymore to guess the `Content-Type`.

The patch for this issue is available [here](https://github.com/symfony/symfony/commit/dca343442e6a954f96a2609e7b4e9c21ed6d74e6) for the 4.4 branch.

Credits -------

I would like to thank Xavier Lacot from JoliCode for reporting & Yonel Ceruto and Tobias Schultze for fixing the issue.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/symfony/http-foundation
Introduced in: 4.4.0Fixed in: 4.4.7
Fixcomposer require symfony/http-foundation:^4.4.7
Packagist/symfony/http-foundation
Introduced in: 5.0.0Fixed in: 5.0.7
Fixcomposer require symfony/http-foundation:^5.0.7
Packagist/symfony/symfony
Introduced in: 4.4.0Fixed in: 4.4.7
Fixcomposer require symfony/symfony:^4.4.7
Packagist/symfony/symfony
Introduced in: 5.0.0Fixed in: 5.0.7
Fixcomposer require symfony/symfony:^5.0.7

References