PT-2018-12713 · Symfony · Symfony

Chaosversum

·

Published

2018-08-03

·

Updated

2022-05-14

·

CVE-2018-14774

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Symfony versions 2.7.0 through 2.7.48 Symfony versions 2.8.0 through 2.8.43 Symfony versions 3.3.0 through 3.3.17 Symfony versions 3.4.0 through 3.4.13 Symfony versions 4.0.0 through 4.0.13 Symfony versions 4.1.0 through 4.1.2
Description An issue was discovered in HttpKernel when using HttpCache. The values of the X-Forwarded-Host headers are implicitly set as trusted, which should be forbidden, leading to potential host header injection.
Recommendations For Symfony versions 2.7.0 through 2.7.48, update to a version outside of this range to resolve the issue. For Symfony versions 2.8.0 through 2.8.43, update to a version outside of this range to resolve the issue. For Symfony versions 3.3.0 through 3.3.17, update to a version outside of this range to resolve the issue. For Symfony versions 3.4.0 through 3.4.13, update to a version outside of this range to resolve the issue. For Symfony versions 4.0.0 through 4.0.13, update to a version outside of this range to resolve the issue. For Symfony versions 4.1.0 through 4.1.2, update to a version outside of this range to resolve the issue.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-01431
CVE-2018-14774
GHSA-66P6-7P29-55P9

Affected Products

Symfony