VDB
Sign up
HIGH7.5

GHSA-wfv7-5x33-v22h

Code injection in the way Symfony implements translation caching in FrameworkBundle

Quick fix

GHSA-wfv7-5x33-v22h — symfony/framework-bundle: upgrade to the fixed version with the command below.

composer require symfony/framework-bundle:^2.3.18

Details

When investigating issue [#11093](https://github.com/symfony/symfony/issues/11093), [Jeremy Derussé](https://connect.sensiolabs.com/profile/jderusse) found a serious code injection issue in the way Symfony implements translation caching in FrameworkBundle.

- Your Symfony application is vulnerable if you meet the following conditions:

- You are using the Symfony translation system from FrameworkBundle (so basically if you are using Symfony full-stack -- you are not affected if you are using the Translation component with Silex for instance); You don't sanitize locales coming from a URL (any route with a _locale argument for instance):

When vulnerable, an attacker can submit a non-valid locale value that can contain some PHP code that will be executed by Symfony. That's because the locale value is dumped into a PHP file generated in the cache without being sanitized first.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/symfony/framework-bundle
Introduced in: 2.0.0Fixed in: 2.3.18
Fixcomposer require symfony/framework-bundle:^2.3.18
Packagist/symfony/framework-bundle
Introduced in: 2.4.0Fixed in: 2.4.8
Fixcomposer require symfony/framework-bundle:^2.4.8
Packagist/symfony/framework-bundle
Introduced in: 2.5.0Fixed in: 2.5.2
Fixcomposer require symfony/framework-bundle:^2.5.2
Packagist/symfony/symfony
Introduced in: 2.0.0Fixed in: 2.3.19
Fixcomposer require symfony/symfony:^2.3.19
Packagist/symfony/symfony
Introduced in: 2.4.0Fixed in: 2.4.9
Fixcomposer require symfony/symfony:^2.4.9
Packagist/symfony/symfony
Introduced in: 2.5.0Fixed in: 2.5.4
Fixcomposer require symfony/symfony:^2.5.4

References