VDB
Sign up
HIGH8.1

GHSA-q8j7-fjh7-25v5

Symfony collectionCascaded and collectionCascadedDeeply fields security bypass

Quick fix

GHSA-q8j7-fjh7-25v5 — symfony/validator: upgrade to the fixed version with the command below.

composer require symfony/validator:^2.0.24

Details

When using the Validator component, if `Symfony\\Component\\Validator\\Mapping\\Cache\\ApcCache` is enabled (or any other cache implementing `Symfony\\Component\\Validator\\Mapping\\Cache\\CacheInterface`), some information is lost during serialization (the `collectionCascaded` and the `collectionCascadedDeeply` fields).

As a consequence, arrays or traversable objects stored in fields using the `@Valid` constraint are not traversed by the validator as soon as the validator configuration is loaded from the cache.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/symfony/validator
Introduced in: 2.0.0Fixed in: 2.0.24
Fixcomposer require symfony/validator:^2.0.24
Packagist/symfony/validator
Introduced in: 2.1.0Fixed in: 2.1.12
Fixcomposer require symfony/validator:^2.1.12
Packagist/symfony/validator
Introduced in: 2.2.0Fixed in: 2.2.5
Fixcomposer require symfony/validator:^2.2.5
Packagist/symfony/validator
Introduced in: 2.3.0Fixed in: 2.3.3
Fixcomposer require symfony/validator:^2.3.3
Packagist/symfony/symfony
Introduced in: 2.0.0Fixed in: 2.0.24
Fixcomposer require symfony/symfony:^2.0.24
Packagist/symfony/symfony
Introduced in: 2.1.0Fixed in: 2.1.12
Fixcomposer require symfony/symfony:^2.1.12
Packagist/symfony/symfony
Introduced in: 2.2.0Fixed in: 2.2.5
Fixcomposer require symfony/symfony:^2.2.5
Packagist/symfony/symfony
Introduced in: 2.3.0Fixed in: 2.3.3
Fixcomposer require symfony/symfony:^2.3.3

References