CRITICAL9.8
GHSA-x92h-wmg2-6hp7
Invalid HTTP method overrides allow possible XSS or other attacks in Symfony
Quick fix
GHSA-x92h-wmg2-6hp7 — symfony/http-foundation: upgrade to the fixed version with the command below.
composer require symfony/http-foundation:^2.7.51Details
In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, HTTP Methods provided as verbs or using the override header may be treated as trusted input, but they are not validated, possibly causing SQL injection or XSS. This is related to symfony/http-foundation.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/symfony/http-foundation
Introduced in:
2.7.0Fixed in: 2.7.51Fix
composer require symfony/http-foundation:^2.7.51Packagist/symfony/http-foundation
Introduced in:
2.8.0Fixed in: 2.8.50Fix
composer require symfony/http-foundation:^2.8.50Packagist/symfony/http-foundation
Introduced in:
3.0.0Fixed in: 3.4.26Fix
composer require symfony/http-foundation:^3.4.26Packagist/symfony/http-foundation
Introduced in:
4.0.0Fixed in: 4.1.12Fix
composer require symfony/http-foundation:^4.1.12Packagist/symfony/http-foundation
Introduced in:
4.2.0Fixed in: 4.2.7Fix
composer require symfony/http-foundation:^4.2.7Packagist/symfony/symfony
Introduced in:
2.7.0Fixed in: 2.7.51Fix
composer require symfony/symfony:^2.7.51Packagist/symfony/symfony
Introduced in:
2.8.0Fixed in: 2.8.50Fix
composer require symfony/symfony:^2.8.50Packagist/symfony/symfony
Introduced in:
3.0.0Fixed in: 3.4.26Fix
composer require symfony/symfony:^3.4.26Packagist/symfony/symfony
Introduced in:
4.0.0Fixed in: 4.1.12Fix
composer require symfony/symfony:^4.1.12Packagist/symfony/symfony
Introduced in:
4.2.0Fixed in: 4.2.7Fix
composer require symfony/symfony:^4.2.7References
- https://nvd.nist.gov/vuln/detail/CVE-2019-10913[ADVISORY]
- https://github.com/symfony/symfony/commit/944e60f083c3bffbc6a0b5112db127a10a66a8ec[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/http-foundation/CVE-2019-10913.yaml[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/symfony/CVE-2019-10913.yaml[WEB]
- https://symfony.com/blog/cve-2019-10913-reject-invalid-http-method-overrides[WEB]
- https://symfony.com/cve-2019-10913[WEB]