VDB
Sign up
CRITICAL9.8

GHSA-x92h-wmg2-6hp7

Invalid HTTP method overrides allow possible XSS or other attacks in Symfony

Quick fix

GHSA-x92h-wmg2-6hp7 — symfony/http-foundation: upgrade to the fixed version with the command below.

composer require symfony/http-foundation:^2.7.51

Details

In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, HTTP Methods provided as verbs or using the override header may be treated as trusted input, but they are not validated, possibly causing SQL injection or XSS. This is related to symfony/http-foundation.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/symfony/http-foundation
Introduced in: 2.7.0Fixed in: 2.7.51
Fixcomposer require symfony/http-foundation:^2.7.51
Packagist/symfony/http-foundation
Introduced in: 2.8.0Fixed in: 2.8.50
Fixcomposer require symfony/http-foundation:^2.8.50
Packagist/symfony/http-foundation
Introduced in: 3.0.0Fixed in: 3.4.26
Fixcomposer require symfony/http-foundation:^3.4.26
Packagist/symfony/http-foundation
Introduced in: 4.0.0Fixed in: 4.1.12
Fixcomposer require symfony/http-foundation:^4.1.12
Packagist/symfony/http-foundation
Introduced in: 4.2.0Fixed in: 4.2.7
Fixcomposer require symfony/http-foundation:^4.2.7
Packagist/symfony/symfony
Introduced in: 2.7.0Fixed in: 2.7.51
Fixcomposer require symfony/symfony:^2.7.51
Packagist/symfony/symfony
Introduced in: 2.8.0Fixed in: 2.8.50
Fixcomposer require symfony/symfony:^2.8.50
Packagist/symfony/symfony
Introduced in: 3.0.0Fixed in: 3.4.26
Fixcomposer require symfony/symfony:^3.4.26
Packagist/symfony/symfony
Introduced in: 4.0.0Fixed in: 4.1.12
Fixcomposer require symfony/symfony:^4.1.12
Packagist/symfony/symfony
Introduced in: 4.2.0Fixed in: 4.2.7
Fixcomposer require symfony/symfony:^4.2.7

References