← Back

CVE-2019-10912

nvd nist
Published: May 16, 2019Modified: Nov 21, 2024

JSON object

Loading...
7.1
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N
Exploitability: 2.8 / Impact: 4.2
Source: NVD

Description

In Symfony before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, it is possible to cache objects that may contain bad user input. On serialization or unserialization, this could result in the deletion of files that the current user has access to. This is related to symfony/cache and symfony/phpunit-bridge.

Affected (4)

Products: Sensiolabs: Symfony
1 product
Symfony
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Sensiolabs
From 2.8.0 to 2.8.50
From 3.4.0 to 3.4.26
From 4.1.0 to 4.1.12
From 4.2.0 to 4.2.7

References (26)

Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.