VDB
Sign up
HIGH8.4

GHSA-qq5c-677p-737q

Symfony vulnerable to command execution hijack on Windows with Process class

Quick fix

GHSA-qq5c-677p-737q — symfony/process: upgrade to the fixed version with the command below.

composer require symfony/process:^5.4.46

Details

### Description

On Windows, when an executable file named `cmd.exe` is located in the current working directory it will be called by the `Process` class when preparing command arguments, leading to possible hijacking.

### Resolution

The `Process` class now uses the absolute path to `cmd.exe`.

The patch for this issue is available [here](https://github.com/symfony/symfony/commit/18ecd03eda3917fdf901a48e72518f911c64a1c9) for branch 5.4.

### Credits

We would like to thank Jordi Boggiano for reporting the issue and Nicolas Grekas for providing the fix.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/symfony/process
Introduced in: 0Fixed in: 5.4.46
Fixcomposer require symfony/process:^5.4.46
Packagist/symfony/process
Introduced in: 6.0.0Fixed in: 6.4.14
Fixcomposer require symfony/process:^6.4.14
Packagist/symfony/process
Introduced in: 7.0.0Fixed in: 7.1.7
Fixcomposer require symfony/process:^7.1.7
Packagist/symfony/symfony
Introduced in: 0Fixed in: 5.4.46
Fixcomposer require symfony/symfony:^5.4.46
Packagist/symfony/symfony
Introduced in: 6.0.0Fixed in: 6.4.14
Fixcomposer require symfony/symfony:^6.4.14
Packagist/symfony/symfony
Introduced in: 7.0.0Fixed in: 7.1.7
Fixcomposer require symfony/symfony:^7.1.7

References