← Back

CVE-2018-11386

nvd nist
Published: Jun 13, 2018Modified: Nov 21, 2024

JSON object

Loading...
5.9
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 2.2 / Impact: 3.6
Source: NVD

Description

An issue was discovered in the HttpFoundation component in Symfony 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x before 4.0.11. The PDOSessionHandler class allows storing sessions on a PDO connection. Under some configurations and with a well-crafted payload, it was possible to do a denial of service on a Symfony application without too much resources.

Affected (6)

1 product
Symfony
1 product
Debian Linux
Configuration A
5 vulnerable
Vulnerable SoftwareAffected Versions
Sensiolabs
From 2.7.0 to 2.7.48
From 2.8.0 to 2.8.41
From 3.3.0 to 3.3.17
From 3.4.0 to 3.4.11
From 4.0.0 to 4.0.11
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 9.0

Timeline

No history available yet.