HIGH7.5
GHSA-xhh6-956q-4q69
Argument injection in a MimeTypeGuesser in Symfony
Quick fix
GHSA-xhh6-956q-4q69 — symfony/http-foundation: upgrade to the fixed version with the command below.
composer require symfony/http-foundation:^2.8.52Details
An issue was discovered in Symfony 2.8.0 through 2.8.50, 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4.3.7. If an application passes unvalidated user input as the file for which MIME type validation should occur, then arbitrary arguments are passed to the underlying file command. This is related to symfony/http-foundation (and symfony/mime in 4.3.x).
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/symfony/http-foundation
Introduced in:
2.0.0Fixed in: 2.8.52Fix
composer require symfony/http-foundation:^2.8.52Packagist/symfony/http-foundation
Introduced in:
3.0.0Fixed in: 3.4.35Fix
composer require symfony/http-foundation:^3.4.35Packagist/symfony/http-foundation
Introduced in:
4.0.0Fixed in: 4.2.12Fix
composer require symfony/http-foundation:^4.2.12Packagist/symfony/http-foundation
Introduced in:
4.3.0Fixed in: 4.3.8Fix
composer require symfony/http-foundation:^4.3.8Packagist/symfony/symfony
Introduced in:
2.0.0Fixed in: 2.8.52Fix
composer require symfony/symfony:^2.8.52Packagist/symfony/symfony
Introduced in:
3.0.0Fixed in: 3.4.35Fix
composer require symfony/symfony:^3.4.35Packagist/symfony/symfony
Introduced in:
4.0.0Fixed in: 4.2.12Fix
composer require symfony/symfony:^4.2.12Packagist/symfony/symfony
Introduced in:
4.3.0Fixed in: 4.3.8Fix
composer require symfony/symfony:^4.3.8References
- https://nvd.nist.gov/vuln/detail/CVE-2019-18888[ADVISORY]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/http-foundation/CVE-2019-18888.yaml[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/mime/CVE-2019-18888.yaml[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/symfony/CVE-2019-18888.yaml[WEB]
- https://github.com/symfony/symfony/releases/tag/v4.3.8[WEB]
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DZNXRVHDQBNZQUCNRVZICPPBFRAUWUJX[WEB]
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UED22BOXTL2SSFMGYKA64ZFHGLLJG3EA[WEB]
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VXEAOEANNIVYANTMOJ42NKSU6BGNBULZ[WEB]
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DZNXRVHDQBNZQUCNRVZICPPBFRAUWUJX[WEB]
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UED22BOXTL2SSFMGYKA64ZFHGLLJG3EA[WEB]
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VXEAOEANNIVYANTMOJ42NKSU6BGNBULZ[WEB]
- https://symfony.com/blog/cve-2019-18888-prevent-argument-injection-in-a-mimetypeguesser[WEB]
- https://symfony.com/blog/symfony-4-3-8-released[WEB]
- https://symfony.com/cve-2019-18888[WEB]