PT-2012-6277 · Symfony · Symfony
Victor Berchet
·
Publicado
2012-12-27
·
Atualizado
2022-05-17
·
CVE-2012-6432
CVSS v2.0
6.8
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Symfony versions 2.0.x through 2.0.20
Symfony versions 2.1.x through 2.1.5
Symfony version 2.2-dev
Description
The issue allows remote attackers to access arbitrary services via vectors involving a URI beginning with a
/api/ internal endpoint, specifically when the internal routes configuration is enabled.Recommendations
For Symfony versions 2.0.x through 2.0.20, update to version 2.0.20 or later.
For Symfony versions 2.1.x through 2.1.5, update to version 2.1.5 or later.
For Symfony version 2.2-dev, consider disabling the internal routes configuration until a patch is available.
Exploit
Correção
Improper Access Control
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Symfony