GHSA-x3cf-w64x-4cp2
Symfony Path Disclosure
Quick fix
GHSA-x3cf-w64x-4cp2 — symfony/symfony: upgrade to the fixed version with the command below.
composer require symfony/symfony:^2.7.50Details
An issue was discovered in Symfony 2.7.x before 2.7.50, 2.8.x before 2.8.49, 3.x before 3.4.20, 4.0.x before 4.0.15, 4.1.x before 4.1.9, and 4.2.x before 4.2.1. When using the scalar type hint `string` in a setter method (e.g. `setName(string $name)`) of a class that's the `data_class` of a form, and when a file upload is submitted to the corresponding field instead of a normal text input, then `UploadedFile::__toString()` is called which will then return and disclose the path of the uploaded file. If combined with a local file inclusion issue in certain circumstances this could escalate it to a Remote Code Execution.
Are you affected?
Enter the version of the package you're using.
Affected packages
2.7.0Fixed in: 2.7.50composer require symfony/symfony:^2.7.502.8.0Fixed in: 2.8.49composer require symfony/symfony:^2.8.493.0.0Fixed in: 3.4.20composer require symfony/symfony:^3.4.204.0.0Fixed in: 4.0.15composer require symfony/symfony:^4.0.154.1.0Fixed in: 4.1.9composer require symfony/symfony:^4.1.94.2.0Fixed in: 4.2.1composer require symfony/symfony:^4.2.1References
- https://nvd.nist.gov/vuln/detail/CVE-2018-19789[ADVISORY]
- https://github.com/symfony/symfony/commit/b65e6f1a47b68f2713b60cdac9cc3a4af62a2d1c[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/form/CVE-2018-19789.yaml[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/symfony/CVE-2018-19789.yaml[WEB]
- https://github.com/symfony/symfony[PACKAGE]
- https://lists.debian.org/debian-lts-announce/2019/03/msg00009.html[WEB]
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4TD3E7FZIXLVFG3SMFJPDEKPZ26TJOW7[WEB]
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JZMRJ7VTHCY5AZK24G4QGX36RLUDTDKE[WEB]
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OA4WVFN5FYPIXAPLWZI6N425JHHDSWAZ[WEB]
- https://seclists.org/bugtraq/2019/May/21[WEB]
- https://symfony.com/blog/cve-2018-19789-disclosure-of-uploaded-files-full-path[WEB]
- https://symfony.com/cve-2018-19789[WEB]
- https://web.archive.org/web/20210124224817/http://www.securityfocus.com/bid/106249[WEB]
- https://www.debian.org/security/2019/dsa-4441[WEB]