← Back

CVE-2019-18889

nvd nist
Published: Nov 21, 2019Modified: Nov 21, 2024

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

An issue was discovered in Symfony 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4.3.7. Serializing certain cache adapter interfaces could result in remote code injection. This is related to symfony/cache.

Affected (4)

1 product
Symfony
1 product
Fedora
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Sensiolabs
From 3.4.0 to 3.4.34
From 4.2.0 to 4.2.11
From 4.3.0 to 4.3.7
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 31

Timeline

No history available yet.