Описание
Symfony Service IDs Allow Injection
In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, when service ids allow user input, this could allow for SQL Injection and remote code execution. This is related to symfony/dependency-injection.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2019-10910
- https://github.com/symfony/symfony/commit/3876c75f858d5d82e2c309698d21af2f1d721afb
- https://github.com/symfony/symfony/commit/4c80c3444854ef384df94deb4acbcef4b5e5243b
- https://github.com/symfony/symfony/commit/d2fb5893923292a1da7985f0b56960b5bb10737b
- https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/dependency-injection/CVE-2019-10910.yaml
- https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/proxy-manager-bridge/CVE-2019-10910.yaml
- https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/symfony/CVE-2019-10910.yaml
- https://symfony.com/blog/cve-2019-10910-check-service-ids-are-valid
- https://symfony.com/cve-2019-10910
- https://www.synology.com/security/advisory/Synology_SA_19_19
Пакеты
symfony/dependency-injection
>= 2.7.0, < 2.7.51
2.7.51
symfony/dependency-injection
>= 2.8.0, < 2.8.50
2.8.50
symfony/dependency-injection
>= 3.0.0, < 3.4.26
3.4.26
symfony/dependency-injection
>= 4.0.0, < 4.1.12
4.1.12
symfony/dependency-injection
>= 4.2.0, < 4.2.7
4.2.7
symfony/proxy-manager-bridge
>= 2.7.0, < 2.7.51
2.7.51
symfony/proxy-manager-bridge
>= 2.8.0, < 2.8.50
2.8.50
symfony/proxy-manager-bridge
>= 3.0.0, < 3.4.26
3.4.26
symfony/proxy-manager-bridge
>= 4.0.0, < 4.1.12
4.1.12
symfony/proxy-manager-bridge
>= 4.2.0, < 4.2.7
4.2.7
symfony/symfony
>= 2.7.0, < 2.7.51
2.7.51
symfony/symfony
>= 2.8.0, < 2.8.50
2.8.50
symfony/symfony
>= 3.0.0, < 3.4.26
3.4.26
symfony/symfony
>= 4.0.0, < 4.1.12
4.1.12
symfony/symfony
>= 4.2.0, < 4.2.7
4.2.7
Связанные уязвимости
In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, when service ids allow user input, this could allow for SQL Injection and remote code execution. This is related to symfony/dependency-injection.
In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, when service ids allow user input, this could allow for SQL Injection and remote code execution. This is related to symfony/dependency-injection.
In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x ...
Уязвимость идентификатора служб «symfony/dependency-injection» программной платформы для разработки и управления веб-приложениями Symfony, связанная с отсутствием мер по защите структур SQL запросов, позволяющая нарушителю выполнить произвольный код через SQL-инъекцию