Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2020-5255

Опубликовано: 30 мар. 2020
Источник: ubuntu
Приоритет: medium
CVSS2: 4
CVSS3: 2.6

Описание

In Symfony before versions 4.4.7 and 5.0.7, when a Response does not contain a Content-Type header, affected versions of Symfony can fallback to the format defined in the Accept header of the request, leading to a possible mismatch between the response's content and Content-Type header. When the response is cached, this can prevent the use of the website by other users. This has been patched in versions 4.4.7 and 5.0.7.

РелизСтатусПримечание
bionic

not-affected

code not present
devel

not-affected

4.4.8-1
eoan

ignored

end of life
esm-apps/bionic

not-affected

code not present
esm-apps/focal

not-affected

code not present
esm-apps/jammy

not-affected

4.4.8-1
esm-apps/xenial

not-affected

code not present
esm-infra-legacy/trusty

DNE

focal

not-affected

code not present
groovy

not-affected

4.4.8-1

Показывать по

4 Medium

CVSS2

2.6 Low

CVSS3

Связанные уязвимости

CVSS3: 2.6
nvd
около 5 лет назад

In Symfony before versions 4.4.7 and 5.0.7, when a `Response` does not contain a `Content-Type` header, affected versions of Symfony can fallback to the format defined in the `Accept` header of the request, leading to a possible mismatch between the response's content and `Content-Type` header. When the response is cached, this can prevent the use of the website by other users. This has been patched in versions 4.4.7 and 5.0.7.

CVSS3: 2.6
debian
около 5 лет назад

In Symfony before versions 4.4.7 and 5.0.7, when a `Response` does not ...

CVSS3: 2.6
github
около 5 лет назад

Prevent cache poisoning via a Response Content-Type header in Symfony

4 Medium

CVSS2

2.6 Low

CVSS3