PT-2012-6277 · Symfony · Symfony
Victor Berchet
·
Published
2012-12-27
·
Updated
2022-05-17
·
CVE-2012-6432
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Symfony versions 2.0.x through 2.0.20
Symfony versions 2.1.x through 2.1.5
Symfony version 2.2-dev
Description
The issue allows remote attackers to access arbitrary services via vectors involving a URI beginning with a
/api/ internal endpoint, specifically when the internal routes configuration is enabled.Recommendations
For Symfony versions 2.0.x through 2.0.20, update to version 2.0.20 or later.
For Symfony versions 2.1.x through 2.1.5, update to version 2.1.5 or later.
For Symfony version 2.2-dev, consider disabling the internal routes configuration until a patch is available.
Exploit
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Symfony