HIGH8.1
GHSA-q8j7-fjh7-25v5
Symfony collectionCascaded and collectionCascadedDeeply fields security bypass
Quick fix
GHSA-q8j7-fjh7-25v5 — symfony/validator: upgrade to the fixed version with the command below.
composer require symfony/validator:^2.0.24Details
When using the Validator component, if `Symfony\\Component\\Validator\\Mapping\\Cache\\ApcCache` is enabled (or any other cache implementing `Symfony\\Component\\Validator\\Mapping\\Cache\\CacheInterface`), some information is lost during serialization (the `collectionCascaded` and the `collectionCascadedDeeply` fields).
As a consequence, arrays or traversable objects stored in fields using the `@Valid` constraint are not traversed by the validator as soon as the validator configuration is loaded from the cache.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/symfony/validator
Introduced in:
2.0.0Fixed in: 2.0.24Fix
composer require symfony/validator:^2.0.24Packagist/symfony/validator
Introduced in:
2.1.0Fixed in: 2.1.12Fix
composer require symfony/validator:^2.1.12Packagist/symfony/validator
Introduced in:
2.2.0Fixed in: 2.2.5Fix
composer require symfony/validator:^2.2.5Packagist/symfony/validator
Introduced in:
2.3.0Fixed in: 2.3.3Fix
composer require symfony/validator:^2.3.3Packagist/symfony/symfony
Introduced in:
2.0.0Fixed in: 2.0.24Fix
composer require symfony/symfony:^2.0.24Packagist/symfony/symfony
Introduced in:
2.1.0Fixed in: 2.1.12Fix
composer require symfony/symfony:^2.1.12Packagist/symfony/symfony
Introduced in:
2.2.0Fixed in: 2.2.5Fix
composer require symfony/symfony:^2.2.5Packagist/symfony/symfony
Introduced in:
2.3.0Fixed in: 2.3.3Fix
composer require symfony/symfony:^2.3.3References
- https://nvd.nist.gov/vuln/detail/CVE-2013-4751[ADVISORY]
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2013-4751[WEB]
- https://exchange.xforce.ibmcloud.com/vulnerabilities/86364[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/symfony/CVE-2013-4751.yaml[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/validator/CVE-2013-4751.yaml[WEB]
- https://github.com/symfony/validator[PACKAGE]
- https://symfony.com/blog/security-releases-symfony-2-0-24-2-1-12-2-2-5-and-2-3-3-released[WEB]
- https://web.archive.org/web/20200228181137/http://www.securityfocus.com/bid/61709[WEB]
- http://lists.fedoraproject.org/pipermail/package-announce/2013-August/114380.html[WEB]
- http://lists.fedoraproject.org/pipermail/package-announce/2013-August/114436.html[WEB]
- http://symfony.com/blog/security-releases-symfony-2-0-24-2-1-12-2-2-5-and-2-3-3-released[WEB]