Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2017-18343

Опубликовано: 20 июл. 2018
Источник: ubuntu
Приоритет: medium
CVSS2: 4.3
CVSS3: 6.1

Описание

** DISPUTED ** The debug handler in Symfony before v2.7.33, 2.8.x before v2.8.26, 3.x before v3.2.13, and 3.3.x before v3.3.6 has XSS via an array key during exception pretty printing in ExceptionHandler.php, as demonstrated by a /_debugbar/open?op=get URI. NOTE: the vendor's position is that this is not a vulnerability because the debug tools are not intended for production use. NOTE: the Symfony Debug component is used by Laravel Debugbar.

РелизСтатусПримечание
artful

ignored

end of life
bionic

not-affected

3.4.6+dfsg-1ubuntu0.1
cosmic

not-affected

3.4.6+dfsg-1ubuntu0.1
devel

not-affected

3.4.22+dfsg-1
disco

not-affected

3.4.22+dfsg-1
eoan

not-affected

3.4.22+dfsg-1
esm-apps/bionic

not-affected

3.4.6+dfsg-1ubuntu0.1
esm-apps/focal

not-affected

3.4.22+dfsg-1
esm-apps/jammy

not-affected

3.4.22+dfsg-1
esm-apps/noble

not-affected

3.4.22+dfsg-1

Показывать по

4.3 Medium

CVSS2

6.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
nvd
почти 7 лет назад

The debug handler in Symfony before v2.7.33, 2.8.x before v2.8.26, 3.x before v3.2.13, and 3.3.x before v3.3.6 has XSS via an array key during exception pretty printing in ExceptionHandler.php, as demonstrated by a /_debugbar/open?op=get URI. NOTE: the vendor's position is that this is not a vulnerability because the debug tools are not intended for production use. NOTE: the Symfony Debug component is used by Laravel Debugbar

CVSS3: 6.1
debian
почти 7 лет назад

The debug handler in Symfony before v2.7.33, 2.8.x before v2.8.26, 3.x ...

CVSS3: 6.1
github
около 3 лет назад

** DISPUTED ** The debug handler in Symfony before v2.7.33, 2.8.x before v2.8.26, 3.x before v3.2.13, and 3.3.x before v3.3.6 has XSS via an array key during exception pretty printing in ExceptionHandler.php, as demonstrated by a /_debugbar/open?op=get URI. NOTE: the vendor's position is that this is not a vulnerability because the debug tools are not intended for production use. NOTE: the Symfony Debug component is used by Laravel Debugbar.

4.3 Medium

CVSS2

6.1 Medium

CVSS3

Уязвимость CVE-2017-18343