HIGH7.1
GHSA-w2fr-65vp-mxw3
Deserialization of untrusted data in Symfony
Quick fix
GHSA-w2fr-65vp-mxw3 — symfony/cache: upgrade to the fixed version with the command below.
composer require symfony/cache:^3.4.26Details
In Symfony before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, it is possible to cache objects that may contain bad user input. On serialization or unserialization, this could result in the deletion of files that the current user has access to. This is related to symfony/cache and symfony/phpunit-bridge.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/symfony/cache
Introduced in:
3.1.0Fixed in: 3.4.26Fix
composer require symfony/cache:^3.4.26Packagist/symfony/cache
Introduced in:
4.0.0Fixed in: 4.1.12Fix
composer require symfony/cache:^4.1.12Packagist/symfony/phpunit-bridge
Introduced in:
2.8.0Fixed in: 2.8.50Fix
composer require symfony/phpunit-bridge:^2.8.50Packagist/symfony/phpunit-bridge
Introduced in:
3.0.0Fixed in: 3.4.26Fix
composer require symfony/phpunit-bridge:^3.4.26Packagist/symfony/phpunit-bridge
Introduced in:
4.0.0Fixed in: 4.1.12Fix
composer require symfony/phpunit-bridge:^4.1.12Packagist/symfony/phpunit-bridge
Introduced in:
4.2.0Fixed in: 4.2.7Fix
composer require symfony/phpunit-bridge:^4.2.7Packagist/symfony/symfony
Introduced in:
2.8.0Fixed in: 2.8.50Fix
composer require symfony/symfony:^2.8.50Packagist/symfony/symfony
Introduced in:
3.0.0Fixed in: 3.4.26Fix
composer require symfony/symfony:^3.4.26Packagist/symfony/symfony
Introduced in:
4.0.0Fixed in: 4.1.12Fix
composer require symfony/symfony:^4.1.12Packagist/symfony/symfony
Introduced in:
4.2.0Fixed in: 4.2.7Fix
composer require symfony/symfony:^4.2.7Packagist/typo3/cms-core
Introduced in:
9.0.0Fixed in: 9.5.8Fix
composer require typo3/cms-core:^9.5.8References
- https://nvd.nist.gov/vuln/detail/CVE-2019-10912[ADVISORY]
- https://github.com/symfony/symfony/commit/4fb975281634b8d49ebf013af9e502e67c28816b[WEB]
- https://www.debian.org/security/2019/dsa-4441[WEB]
- https://typo3.org/security/advisory/typo3-core-sa-2019-016[WEB]
- https://symfony.com/cve-2019-10912[WEB]
- https://symfony.com/blog/cve-2019-10912-prevent-destructors-with-side-effects-from-being-unserialized[WEB]
- https://seclists.org/bugtraq/2019/May/21[WEB]
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZLOZX5BZMQKWG7PJRQL6MB5CAMKBQAWD[WEB]
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RTJGZJLPG5FHKFH7KNAKNTWOGBB6LXAL[WEB]
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MDSM576XIOVXVCMHNJHLBBZBTOD62LDA[WEB]
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LFARAUAWZE4UDSKVDWRD35D75HI5UGSD[WEB]
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BHHIG4GMSGEIDT3RITSW7GJ5NT6IBHXU[WEB]
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BAC2TQVEEH5FDJSSWPM2BCRIPTCOEMMO[WEB]
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6QEAOZXVNDA63537A2OIH4QE77EKZR5O[WEB]
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/42UEKSLKJB72P24JBWVN6AADHLMYSUQD[WEB]
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZLOZX5BZMQKWG7PJRQL6MB5CAMKBQAWD[WEB]
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RTJGZJLPG5FHKFH7KNAKNTWOGBB6LXAL[WEB]
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MDSM576XIOVXVCMHNJHLBBZBTOD62LDA[WEB]
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LFARAUAWZE4UDSKVDWRD35D75HI5UGSD[WEB]
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BHHIG4GMSGEIDT3RITSW7GJ5NT6IBHXU[WEB]
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BAC2TQVEEH5FDJSSWPM2BCRIPTCOEMMO[WEB]
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6QEAOZXVNDA63537A2OIH4QE77EKZR5O[WEB]
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/42UEKSLKJB72P24JBWVN6AADHLMYSUQD[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/typo3/cms/CVE-2019-10912.yaml[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/typo3/cms-core/CVE-2019-10912.yaml[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/symfony/CVE-2019-10912.yaml[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/phpunit-bridge/CVE-2019-10912.yaml[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/cache/CVE-2019-10912.yaml[WEB]