PT-2018-12713 · Symfony · Symfony

·

CVE-2018-14774

·

Published

2018-08-03

·

Updated

2022-05-14

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Symfony versions 2.7.0 through 2.7.48 Symfony versions 2.8.0 through 2.8.43 Symfony versions 3.3.0 through 3.3.17 Symfony versions 3.4.0 through 3.4.13 Symfony versions 4.0.0 through 4.0.13 Symfony versions 4.1.0 through 4.1.2
Description An issue was discovered in HttpKernel when using HttpCache. The values of the X-Forwarded-Host headers are implicitly set as trusted, which should be forbidden, leading to potential host header injection.
Recommendations For Symfony versions 2.7.0 through 2.7.48, update to a version outside of this range to resolve the issue. For Symfony versions 2.8.0 through 2.8.43, update to a version outside of this range to resolve the issue. For Symfony versions 3.3.0 through 3.3.17, update to a version outside of this range to resolve the issue. For Symfony versions 3.4.0 through 3.4.13, update to a version outside of this range to resolve the issue. For Symfony versions 4.0.0 through 4.0.13, update to a version outside of this range to resolve the issue. For Symfony versions 4.1.0 through 4.1.2, update to a version outside of this range to resolve the issue.

Fix

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-01431
CVE-2018-14774
GHSA-66P6-7P29-55P9

Affected Products

Symfony