Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2020-15094

Опубликовано: 02 сент. 2020
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 7.5
CVSS3: 8

Описание

In Symfony before versions 4.4.13 and 5.1.5, the CachingHttpClient class from the HttpClient Symfony component relies on the HttpCache class to handle requests. HttpCache uses internal headers like X-Body-Eval and X-Body-File to control the restoration of cached responses. The class was initially written with surrogate caching and ESI support in mind (all HTTP calls come from a trusted backend in that scenario). But when used by CachingHttpClient and if an attacker can control the response for a request being made by the CachingHttpClient, remote code execution is possible. This has been fixed in versions 4.4.13 and 5.1.5.

РелизСтатусПримечание
bionic

not-affected

code not present
devel

not-affected

4.4.13+dfsg-1
esm-apps/bionic

not-affected

code not present
esm-apps/focal

not-affected

code not present
esm-apps/jammy

not-affected

4.4.13+dfsg-1
esm-apps/xenial

not-affected

code not present
esm-infra-legacy/trusty

DNE

focal

not-affected

code not present
groovy

ignored

end of life
hirsute

ignored

end of life

Показывать по

EPSS

Процентиль: 84%
0.02248
Низкий

7.5 High

CVSS2

8 High

CVSS3

Связанные уязвимости

CVSS3: 8
nvd
почти 5 лет назад

In Symfony before versions 4.4.13 and 5.1.5, the CachingHttpClient class from the HttpClient Symfony component relies on the HttpCache class to handle requests. HttpCache uses internal headers like X-Body-Eval and X-Body-File to control the restoration of cached responses. The class was initially written with surrogate caching and ESI support in mind (all HTTP calls come from a trusted backend in that scenario). But when used by CachingHttpClient and if an attacker can control the response for a request being made by the CachingHttpClient, remote code execution is possible. This has been fixed in versions 4.4.13 and 5.1.5.

CVSS3: 8
debian
почти 5 лет назад

In Symfony before versions 4.4.13 and 5.1.5, the CachingHttpClient cla ...

CVSS3: 8
github
почти 5 лет назад

RCE in Symfony

EPSS

Процентиль: 84%
0.02248
Низкий

7.5 High

CVSS2

8 High

CVSS3