Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-5255

Опубликовано: 30 мар. 2020
Источник: nvd
CVSS3: 2.6
CVSS3: 4.3
CVSS2: 4
EPSS Низкий

Описание

In Symfony before versions 4.4.7 and 5.0.7, when a Response does not contain a Content-Type header, affected versions of Symfony can fallback to the format defined in the Accept header of the request, leading to a possible mismatch between the response's content and Content-Type header. When the response is cached, this can prevent the use of the website by other users. This has been patched in versions 4.4.7 and 5.0.7.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
Версия от 4.4.0 (включая) до 4.4.7 (исключая)
cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
Версия от 5.0.0 (включая) до 5.0.7 (исключая)

EPSS

Процентиль: 58%
0.00374
Низкий

2.6 Low

CVSS3

4.3 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-435
CWE-20

Связанные уязвимости

CVSS3: 2.6
ubuntu
около 5 лет назад

In Symfony before versions 4.4.7 and 5.0.7, when a `Response` does not contain a `Content-Type` header, affected versions of Symfony can fallback to the format defined in the `Accept` header of the request, leading to a possible mismatch between the response's content and `Content-Type` header. When the response is cached, this can prevent the use of the website by other users. This has been patched in versions 4.4.7 and 5.0.7.

CVSS3: 2.6
debian
около 5 лет назад

In Symfony before versions 4.4.7 and 5.0.7, when a `Response` does not ...

CVSS3: 2.6
github
около 5 лет назад

Prevent cache poisoning via a Response Content-Type header in Symfony

EPSS

Процентиль: 58%
0.00374
Низкий

2.6 Low

CVSS3

4.3 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-435
CWE-20