VDB
Sign up
MEDIUM6.5

GHSA-q3j3-w37x-hq2q

Webcache Poisoning in symfony/http-kernel

Quick fix

GHSA-q3j3-w37x-hq2q — symfony/http-kernel: upgrade to the fixed version with the command below.

composer require symfony/http-kernel:^5.3.12

Details

Description -----------

When a Symfony application is running behind a proxy or a load-balancer, you can tell Symfony to look for the `X-Forwarded-*` HTTP headers. HTTP headers that are not part of the "trusted_headers" allowed list are ignored and protect you from "Cache poisoning" attacks.

In Symfony 5.2, we've added support for the `X-Forwarded-Prefix` header, but this header was accessible in sub-requests, even if it was not part of the "trusted_headers" allowed list. An attacker could leverage this opportunity to forge requests containing a `X-Forwarded-Prefix` HTTP header, leading to a web cache poisoning issue.

Resolution ----------

Symfony now ensures that the `X-Forwarded-Prefix` HTTP header is not forwarded to sub-requests when it is not trusted.

The patch for this issue is available [here](https://github.com/symfony/symfony/commit/95dcf51682029e89450aee86267e3d553aa7c487) for branch 5.3.

Credits -------

We would like to thank Soner Sayakci for reporting the issue and Jérémy Derussé for fixing the issue.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/symfony/http-kernel
Introduced in: 5.2.0Fixed in: 5.3.12
Fixcomposer require symfony/http-kernel:^5.3.12
Packagist/symfony/symfony
Introduced in: 5.2.0Fixed in: 5.3.12
Fixcomposer require symfony/symfony:^5.3.12

References