Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9c3x-r3wp-mgxm

Опубликовано: 06 нояб. 2024
Источник: github
Github: Прошло ревью
CVSS4: 2.3
CVSS3: 3.1

Описание

Symfony allows internal address and port enumeration by NoPrivateNetworkHttpClient

Description

When using the NoPrivateNetworkHttpClient, some internal information is still leaking during host resolution, which leads to possible IP/port enumeration.

Resolution

The NoPrivateNetworkHttpClient now filters blocked IPs earlier to prevent such leaks.

The fisrt patch for this issue is available here for branch 5.4.

The second one is available here for branch 5.4 also.

Credits

We would like to thank Linus Karlsson and Chris Smith for reporting the issue and Nicolas Grekas for providing the fix.

Пакеты

Наименование

symfony/http-client

composer
Затронутые версииВерсия исправления

>= 4.3.0, < 5.4.47

5.4.47

Наименование

symfony/http-client

composer
Затронутые версииВерсия исправления

>= 6.0.0, < 6.4.15

6.4.15

Наименование

symfony/http-client

composer
Затронутые версииВерсия исправления

>= 7.0.0, < 7.1.8

7.1.8

Наименование

symfony/symfony

composer
Затронутые версииВерсия исправления

>= 4.3.0, < 5.4.47

5.4.47

Наименование

symfony/symfony

composer
Затронутые версииВерсия исправления

>= 6.0.0, < 6.4.15

6.4.15

Наименование

symfony/symfony

composer
Затронутые версииВерсия исправления

>= 7.0.0, < 7.1.8

7.1.8

EPSS

Процентиль: 6%
0.00027
Низкий

2.3 Low

CVSS4

3.1 Low

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 3.1
ubuntu
9 месяцев назад

symfony/http-client is a module for the Symphony PHP framework which provides powerful methods to fetch HTTP resources synchronously or asynchronously. When using the `NoPrivateNetworkHttpClient`, some internal information is still leaking during host resolution, which leads to possible IP/port enumeration. As of versions 5.4.46, 6.4.14, and 7.1.7 the `NoPrivateNetworkHttpClient` now filters blocked IPs earlier to prevent such leaks. All users are advised to upgrade. There are no known workarounds for this vulnerability.

CVSS3: 3.1
nvd
9 месяцев назад

symfony/http-client is a module for the Symphony PHP framework which provides powerful methods to fetch HTTP resources synchronously or asynchronously. When using the `NoPrivateNetworkHttpClient`, some internal information is still leaking during host resolution, which leads to possible IP/port enumeration. As of versions 5.4.46, 6.4.14, and 7.1.7 the `NoPrivateNetworkHttpClient` now filters blocked IPs earlier to prevent such leaks. All users are advised to upgrade. There are no known workarounds for this vulnerability.

CVSS3: 3.1
debian
9 месяцев назад

symfony/http-client is a module for the Symphony PHP framework which p ...

CVSS3: 3.1
fstec
9 месяцев назад

Уязвимость компонента http-client программной платформы для разработки и управления веб-приложениями Symfony, позволяющая нарушителю получить доступ к конфиденциальным данным

CVSS3: 7.3
redos
около 1 месяца назад

Множественные уязвимости php-symfony4

EPSS

Процентиль: 6%
0.00027
Низкий

2.3 Low

CVSS4

3.1 Low

CVSS3

Дефекты

CWE-200