PT-2012-6277 · Symfony · Symfony

Victor Berchet

·

Published

2012-12-27

·

Updated

2022-05-17

·

CVE-2012-6432

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Symfony versions 2.0.x through 2.0.20 Symfony versions 2.1.x through 2.1.5 Symfony version 2.2-dev
Description The issue allows remote attackers to access arbitrary services via vectors involving a URI beginning with a /api/ internal endpoint, specifically when the internal routes configuration is enabled.
Recommendations For Symfony versions 2.0.x through 2.0.20, update to version 2.0.20 or later. For Symfony versions 2.1.x through 2.1.5, update to version 2.1.5 or later. For Symfony version 2.2-dev, consider disabling the internal routes configuration until a patch is available.

Exploit

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2012-6432
GHSA-89CP-FVCC-HXH7

Affected Products

Symfony