Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9c3x-r3wp-mgxm

Опубликовано: 06 нояб. 2024
Источник: github
Github: Прошло ревью
CVSS4: 2.3
CVSS3: 3.1

Описание

Symfony allows internal address and port enumeration by NoPrivateNetworkHttpClient

Description

When using the NoPrivateNetworkHttpClient, some internal information is still leaking during host resolution, which leads to possible IP/port enumeration.

Resolution

The NoPrivateNetworkHttpClient now filters blocked IPs earlier to prevent such leaks.

The fisrt patch for this issue is available here for branch 5.4.

The second one is available here for branch 5.4 also.

Credits

We would like to thank Linus Karlsson and Chris Smith for reporting the issue and Nicolas Grekas for providing the fix.

Пакеты

Наименование

symfony/http-client

composer
Затронутые версииВерсия исправления

>= 4.3.0, < 5.4.47

5.4.47

Наименование

symfony/http-client

composer
Затронутые версииВерсия исправления

>= 6.0.0, < 6.4.15

6.4.15

Наименование

symfony/http-client

composer
Затронутые версииВерсия исправления

>= 7.0.0, < 7.1.8

7.1.8

Наименование

symfony/symfony

composer
Затронутые версииВерсия исправления

>= 4.3.0, < 5.4.47

5.4.47

Наименование

symfony/symfony

composer
Затронутые версииВерсия исправления

>= 6.0.0, < 6.4.15

6.4.15

Наименование

symfony/symfony

composer
Затронутые версииВерсия исправления

>= 7.0.0, < 7.1.8

7.1.8

EPSS

Процентиль: 8%
0.00032
Низкий

2.3 Low

CVSS4

3.1 Low

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 3.1
ubuntu
12 месяцев назад

symfony/http-client is a module for the Symphony PHP framework which provides powerful methods to fetch HTTP resources synchronously or asynchronously. When using the `NoPrivateNetworkHttpClient`, some internal information is still leaking during host resolution, which leads to possible IP/port enumeration. As of versions 5.4.46, 6.4.14, and 7.1.7 the `NoPrivateNetworkHttpClient` now filters blocked IPs earlier to prevent such leaks. All users are advised to upgrade. There are no known workarounds for this vulnerability.

CVSS3: 3.1
nvd
12 месяцев назад

symfony/http-client is a module for the Symphony PHP framework which provides powerful methods to fetch HTTP resources synchronously or asynchronously. When using the `NoPrivateNetworkHttpClient`, some internal information is still leaking during host resolution, which leads to possible IP/port enumeration. As of versions 5.4.46, 6.4.14, and 7.1.7 the `NoPrivateNetworkHttpClient` now filters blocked IPs earlier to prevent such leaks. All users are advised to upgrade. There are no known workarounds for this vulnerability.

CVSS3: 3.1
debian
12 месяцев назад

symfony/http-client is a module for the Symphony PHP framework which p ...

CVSS3: 3.1
fstec
около 1 года назад

Уязвимость компонента http-client программной платформы для разработки и управления веб-приложениями Symfony, позволяющая нарушителю получить доступ к конфиденциальным данным

CVSS3: 7.3
redos
4 месяца назад

Множественные уязвимости php-symfony4

EPSS

Процентиль: 8%
0.00032
Низкий

2.3 Low

CVSS4

3.1 Low

CVSS3

Дефекты

CWE-200