Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-66p6-7p29-55p9

Опубликовано: 14 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.2

Описание

Symfony Host Header Injection

An issue was discovered in HttpKernel in Symfony 2.7.0 through 2.7.48, 2.8.0 through 2.8.43, 3.3.0 through 3.3.17, 3.4.0 through 3.4.13, 4.0.0 through 4.0.13, and 4.1.0 through 4.1.2. When using HttpCache, the values of the X-Forwarded-Host headers are implicitly set as trusted while this should be forbidden, leading to potential host header injection.

Пакеты

Наименование

symfony/symfony

composer
Затронутые версииВерсия исправления

>= 2.7.0, <= 2.7.48

2.7.49

Наименование

symfony/symfony

composer
Затронутые версииВерсия исправления

>= 2.8.0, <= 2.8.43

2.8.44

Наименование

symfony/symfony

composer
Затронутые версииВерсия исправления

>= 3.3.0, <= 3.3.17

3.3.18

Наименование

symfony/symfony

composer
Затронутые версииВерсия исправления

>= 3.4.0, <= 3.4.13

3.4.14

Наименование

symfony/symfony

composer
Затронутые версииВерсия исправления

>= 4.0.0, <= 4.0.13

4.0.14

Наименование

symfony/symfony

composer
Затронутые версииВерсия исправления

>= 4.1.0, <= 4.1.2

4.1.3

EPSS

Процентиль: 37%
0.00153
Низкий

7.2 High

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 7.2
ubuntu
почти 7 лет назад

An issue was discovered in HttpKernel in Symfony 2.7.0 through 2.7.48, 2.8.0 through 2.8.43, 3.3.0 through 3.3.17, 3.4.0 through 3.4.13, 4.0.0 through 4.0.13, and 4.1.0 through 4.1.2. When using HttpCache, the values of the X-Forwarded-Host headers are implicitly set as trusted while this should be forbidden, leading to potential host header injection.

CVSS3: 7.2
nvd
почти 7 лет назад

An issue was discovered in HttpKernel in Symfony 2.7.0 through 2.7.48, 2.8.0 through 2.8.43, 3.3.0 through 3.3.17, 3.4.0 through 3.4.13, 4.0.0 through 4.0.13, and 4.1.0 through 4.1.2. When using HttpCache, the values of the X-Forwarded-Host headers are implicitly set as trusted while this should be forbidden, leading to potential host header injection.

CVSS3: 7.2
debian
почти 7 лет назад

An issue was discovered in HttpKernel in Symfony 2.7.0 through 2.7.48, ...

EPSS

Процентиль: 37%
0.00153
Низкий

7.2 High

CVSS3

Дефекты

CWE-20