CRITICAL9.8
GHSA-pgwj-prpq-jpc2
Symfony Service IDs Allow Injection
Quick fix
GHSA-pgwj-prpq-jpc2 — symfony/dependency-injection: upgrade to the fixed version with the command below.
composer require symfony/dependency-injection:^2.7.51Details
In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, when service ids allow user input, this could allow for SQL Injection and remote code execution. This is related to symfony/dependency-injection.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/symfony/dependency-injection
Introduced in:
2.7.0Fixed in: 2.7.51Fix
composer require symfony/dependency-injection:^2.7.51Packagist/symfony/dependency-injection
Introduced in:
2.8.0Fixed in: 2.8.50Fix
composer require symfony/dependency-injection:^2.8.50Packagist/symfony/dependency-injection
Introduced in:
3.0.0Fixed in: 3.4.26Fix
composer require symfony/dependency-injection:^3.4.26Packagist/symfony/dependency-injection
Introduced in:
4.0.0Fixed in: 4.1.12Fix
composer require symfony/dependency-injection:^4.1.12Packagist/symfony/dependency-injection
Introduced in:
4.2.0Fixed in: 4.2.7Fix
composer require symfony/dependency-injection:^4.2.7Packagist/symfony/proxy-manager-bridge
Introduced in:
2.7.0Fixed in: 2.7.51Fix
composer require symfony/proxy-manager-bridge:^2.7.51Packagist/symfony/proxy-manager-bridge
Introduced in:
2.8.0Fixed in: 2.8.50Fix
composer require symfony/proxy-manager-bridge:^2.8.50Packagist/symfony/proxy-manager-bridge
Introduced in:
3.0.0Fixed in: 3.4.26Fix
composer require symfony/proxy-manager-bridge:^3.4.26Packagist/symfony/proxy-manager-bridge
Introduced in:
4.0.0Fixed in: 4.1.12Fix
composer require symfony/proxy-manager-bridge:^4.1.12Packagist/symfony/proxy-manager-bridge
Introduced in:
4.2.0Fixed in: 4.2.7Fix
composer require symfony/proxy-manager-bridge:^4.2.7Packagist/symfony/symfony
Introduced in:
2.7.0Fixed in: 2.7.51Fix
composer require symfony/symfony:^2.7.51Packagist/symfony/symfony
Introduced in:
2.8.0Fixed in: 2.8.50Fix
composer require symfony/symfony:^2.8.50Packagist/symfony/symfony
Introduced in:
3.0.0Fixed in: 3.4.26Fix
composer require symfony/symfony:^3.4.26Packagist/symfony/symfony
Introduced in:
4.0.0Fixed in: 4.1.12Fix
composer require symfony/symfony:^4.1.12Packagist/symfony/symfony
Introduced in:
4.2.0Fixed in: 4.2.7Fix
composer require symfony/symfony:^4.2.7References
- https://nvd.nist.gov/vuln/detail/CVE-2019-10910[ADVISORY]
- https://github.com/symfony/symfony/commit/3876c75f858d5d82e2c309698d21af2f1d721afb[WEB]
- https://github.com/symfony/symfony/commit/4c80c3444854ef384df94deb4acbcef4b5e5243b[WEB]
- https://github.com/symfony/symfony/commit/d2fb5893923292a1da7985f0b56960b5bb10737b[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/dependency-injection/CVE-2019-10910.yaml[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/proxy-manager-bridge/CVE-2019-10910.yaml[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/symfony/CVE-2019-10910.yaml[WEB]
- https://github.com/symfony/symfony[PACKAGE]
- https://symfony.com/blog/cve-2019-10910-check-service-ids-are-valid[WEB]
- https://symfony.com/cve-2019-10910[WEB]
- https://www.synology.com/security/advisory/Synology_SA_19_19[WEB]