MEDIUM5.9
GHSA-r2rq-3h56-fqm4
Symfony DoS
Quick fix
GHSA-r2rq-3h56-fqm4 — symfony/symfony: upgrade to the fixed version with the command below.
composer require symfony/symfony:^2.7.48Details
An issue was discovered in the HttpFoundation component in Symfony 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x before 4.0.11. The PDOSessionHandler class allows storing sessions on a PDO connection. Under some configurations and with a well-crafted payload, it was possible to do a denial of service on a Symfony application without too much resources.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/symfony/symfony
Introduced in:
2.7.0Fixed in: 2.7.48Fix
composer require symfony/symfony:^2.7.48Packagist/symfony/symfony
Introduced in:
2.8.0Fixed in: 2.8.41Fix
composer require symfony/symfony:^2.8.41Packagist/symfony/symfony
Introduced in:
3.3.0Fixed in: 3.3.17Fix
composer require symfony/symfony:^3.3.17Packagist/symfony/symfony
Introduced in:
3.4.0Fixed in: 3.4.11Fix
composer require symfony/symfony:^3.4.11Packagist/symfony/symfony
Introduced in:
4.0.0Fixed in: 4.0.11Fix
composer require symfony/symfony:^4.0.11Packagist/symfony/http-foundation
Introduced in:
2.7.0Fixed in: 2.7.48Fix
composer require symfony/http-foundation:^2.7.48Packagist/symfony/http-foundation
Introduced in:
2.8.0Fixed in: 2.8.41Fix
composer require symfony/http-foundation:^2.8.41Packagist/symfony/http-foundation
Introduced in:
3.3.0Fixed in: 3.3.17Fix
composer require symfony/http-foundation:^3.3.17Packagist/symfony/http-foundation
Introduced in:
3.4.0Fixed in: 3.4.11Fix
composer require symfony/http-foundation:^3.4.11Packagist/symfony/http-foundation
Introduced in:
4.0.0Fixed in: 4.0.11Fix
composer require symfony/http-foundation:^4.0.11References
- https://nvd.nist.gov/vuln/detail/CVE-2018-11386[ADVISORY]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/http-foundation/CVE-2018-11386.yaml[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/symfony/CVE-2018-11386.yaml[WEB]
- https://github.com/symfony/symfony[PACKAGE]
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/G4XNBMFW33H47O5TZGA7JYCVLDBCXAJV[WEB]
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UBQK7JDXIELADIPGZIOUCZKMAJM5LSBW[WEB]
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WU5N2TZFNGXDGMXMPP7LZCWTFLENF6WH[WEB]
- https://symfony.com/blog/cve-2018-11386-denial-of-service-when-using-pdosessionhandler[WEB]
- https://symfony.com/cve-2018-11386[WEB]
- https://www.debian.org/security/2018/dsa-4262[WEB]