VDB
Sign up
HIGH8.1

GHSA-q8hg-pf8v-cxrv

Symfony Http-Kernel has non-constant time comparison in UriSigner

Quick fix

GHSA-q8hg-pf8v-cxrv — symfony/http-kernel: upgrade to the fixed version with the command below.

composer require symfony/http-kernel:^2.8.52

Details

When checking the signature of an URI (an ESI fragment URL for instance), the URISigner did not used a constant time string comparison function, resulting in a potential remote timing attack vulnerability.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/symfony/http-kernel
Introduced in: 2.2.0Fixed in: 2.8.52
Fixcomposer require symfony/http-kernel:^2.8.52
Packagist/symfony/http-kernel
Introduced in: 3.0.0Fixed in: 3.4.35
Fixcomposer require symfony/http-kernel:^3.4.35
Packagist/symfony/http-kernel
Introduced in: 4.0.0Fixed in: 4.2.12
Fixcomposer require symfony/http-kernel:^4.2.12
Packagist/symfony/http-kernel
Introduced in: 4.3.0Fixed in: 4.3.8
Fixcomposer require symfony/http-kernel:^4.3.8
Packagist/symfony/symfony
Introduced in: 2.2.0Fixed in: 2.8.52
Fixcomposer require symfony/symfony:^2.8.52
Packagist/symfony/symfony
Introduced in: 3.0.0Fixed in: 3.4.35
Fixcomposer require symfony/symfony:^3.4.35
Packagist/symfony/symfony
Introduced in: 4.0.0Fixed in: 4.2.12
Fixcomposer require symfony/symfony:^4.2.12
Packagist/symfony/symfony
Introduced in: 4.3.0Fixed in: 4.3.8
Fixcomposer require symfony/symfony:^4.3.8

References