Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-64500

Опубликовано: 12 нояб. 2025
Источник: debian
EPSS Низкий

Описание

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Symfony's HttpFoundation component defines an object-oriented layer for the HTTP specification. Starting in version 2.0.0 and prior to version 5.4.50, 6.4.29, and 7.3.7, the `Request` class improperly interprets some `PATH_INFO` in a way that leads to representing some URLs with a path that doesn't start with a `/`. This can allow bypassing some access control rules that are built with this `/`-prefix assumption. Starting in versions 5.4.50, 6.4.29, and 7.3.7, the `Request` class now ensures that URL paths always start with a `/`.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
symfonyfixed8.0.0~beta2+dfsg-2experimentalpackage
symfonyfixed7.4.0~rc1+dfsg-1package
symfonyfixed6.4.21+dfsg-2+deb13u1trixiepackage
symfonyfixed5.4.23+dfsg-1+deb12u5bookwormpackage
symfonypostponedbullseyepackage

Примечания

  • https://github.com/advisories/GHSA-3rg7-wf37-54rm

  • https://github.com/symfony/symfony/commit/9962b91b12bb791322fa73836b350836b6db7cac (v5.4.50, v6.4.29, v7.3.7)

EPSS

Процентиль: 9%
0.00031
Низкий

Связанные уязвимости

CVSS3: 7.3
ubuntu
2 месяца назад

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Symfony's HttpFoundation component defines an object-oriented layer for the HTTP specification. Starting in version 2.0.0 and prior to version 5.4.50, 6.4.29, and 7.3.7, the `Request` class improperly interprets some `PATH_INFO` in a way that leads to representing some URLs with a path that doesn't start with a `/`. This can allow bypassing some access control rules that are built with this `/`-prefix assumption. Starting in versions 5.4.50, 6.4.29, and 7.3.7, the `Request` class now ensures that URL paths always start with a `/`.

CVSS3: 7.3
nvd
2 месяца назад

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Symfony's HttpFoundation component defines an object-oriented layer for the HTTP specification. Starting in version 2.0.0 and prior to version 5.4.50, 6.4.29, and 7.3.7, the `Request` class improperly interprets some `PATH_INFO` in a way that leads to representing some URLs with a path that doesn't start with a `/`. This can allow bypassing some access control rules that are built with this `/`-prefix assumption. Starting in versions 5.4.50, 6.4.29, and 7.3.7, the `Request` class now ensures that URL paths always start with a `/`.

CVSS3: 7.3
redos
24 дня назад

Уязвимость php-symfony4

CVSS3: 7.3
github
2 месяца назад

Symfony's incorrect parsing of PATH_INFO can lead to limited authorization bypass

EPSS

Процентиль: 9%
0.00031
Низкий
Уязвимость CVE-2025-64500