VDB
Sign up
LOW3.1

GHSA-mrqx-rp3w-jpjp

Symfony vulnerable to open redirect via browser-sanitized URLs

Quick fix

GHSA-mrqx-rp3w-jpjp — symfony/http-foundation: upgrade to the fixed version with the command below.

composer require symfony/http-foundation:^5.4.46

Details

### Description

The `Request` class, does not parse URI with special characters the same way browsers do. As a result, an attacker can trick a validator relying on the `Request` class to redirect users to another domain.

### Resolution

The `Request::create` methods now assert the URI does not contain invalid characters as defined by https://url.spec.whatwg.org/

The patch for this issue is available [here](https://github.com/symfony/symfony/commit/5a9b08e5740af795854b1b639b7d45b9cbfe8819) for branch 5.4.

### Credits

We would like to thank Sam Mush - IPASSLab && ZGC Lab for reporting the issue and Nicolas Grekas for providing the fix.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/symfony/http-foundation
Introduced in: 0Fixed in: 5.4.46
Fixcomposer require symfony/http-foundation:^5.4.46
Packagist/symfony/http-foundation
Introduced in: 6.0.0Fixed in: 6.4.14
Fixcomposer require symfony/http-foundation:^6.4.14
Packagist/symfony/http-foundation
Introduced in: 7.0.0Fixed in: 7.1.7
Fixcomposer require symfony/http-foundation:^7.1.7

References