MEDIUM6.1
GHSA-r7p7-qr7p-2rrf
Symfony Open Redirect
Quick fix
GHSA-r7p7-qr7p-2rrf — symfony/symfony: upgrade to the fixed version with the command below.
composer require symfony/symfony:^2.7.38Details
An issue was discovered in Symfony 2.7.x before 2.7.38, 2.8.x before 2.8.31, 3.2.x before 3.2.14, and 3.3.x before 3.3.13. `DefaultAuthenticationSuccessHandler` or `DefaultAuthenticationFailureHandler` takes the content of the `_target_path` parameter and generates a redirect response, but no check is performed on the path, which could be an absolute URL to an external domain. This Open redirect vulnerability can be exploited for example to mount effective phishing attacks.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/symfony/symfony
Introduced in:
2.7.0Fixed in: 2.7.38Fix
composer require symfony/symfony:^2.7.38Packagist/symfony/symfony
Introduced in:
2.8.0Fixed in: 2.8.31Fix
composer require symfony/symfony:^2.8.31Packagist/symfony/symfony
Introduced in:
3.2.0Fixed in: 3.2.14Fix
composer require symfony/symfony:^3.2.14Packagist/symfony/symfony
Introduced in:
3.3.0Fixed in: 3.3.13Fix
composer require symfony/symfony:^3.3.13Packagist/symfony/security-http
Introduced in:
2.7.0Fixed in: 2.7.38Fix
composer require symfony/security-http:^2.7.38Packagist/symfony/security-http
Introduced in:
2.8.0Fixed in: 2.8.31Fix
composer require symfony/security-http:^2.8.31Packagist/symfony/security-http
Introduced in:
3.2.0Fixed in: 3.2.14Fix
composer require symfony/security-http:^3.2.14Packagist/symfony/security-http
Introduced in:
3.3.0Fixed in: 3.3.13Fix
composer require symfony/security-http:^3.3.13Packagist/symfony/security
Introduced in:
2.7.0Fixed in: 2.7.38Fix
composer require symfony/security:^2.7.38Packagist/symfony/security
Introduced in:
2.8.0Fixed in: 2.8.31Fix
composer require symfony/security:^2.8.31Packagist/symfony/security
Introduced in:
3.2.0Fixed in: 3.2.14Fix
composer require symfony/security:^3.2.14Packagist/symfony/security
Introduced in:
3.3.0Fixed in: 3.3.13Fix
composer require symfony/security:^3.3.13References
- https://nvd.nist.gov/vuln/detail/CVE-2017-16652[ADVISORY]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/security-http/CVE-2017-16652.yaml[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/security/CVE-2017-16652.yaml[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/symfony/CVE-2017-16652.yaml[WEB]
- https://github.com/symfony/symfony[PACKAGE]
- https://lists.debian.org/debian-lts-announce/2019/03/msg00009.html[WEB]
- https://symfony.com/blog/cve-2017-16652-open-redirect-vulnerability-on-security-handlers[WEB]
- https://symfony.com/cve-2017-16652[WEB]