| Vulnerability Name: | CVE-2018-11408 (CCN-144826) | ||||||||||||||||||||||||||||||||||||
| Assigned: | 2018-05-25 | ||||||||||||||||||||||||||||||||||||
| Published: | 2018-05-25 | ||||||||||||||||||||||||||||||||||||
| Updated: | 2019-03-13 | ||||||||||||||||||||||||||||||||||||
| Summary: | The security handlers in the Security component in Symfony in 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x before 4.0.11 have an Open redirect vulnerability when security.http_utils is inlined by a container. Note: this issue exists because of an incomplete fix for CVE-2017-16652. | ||||||||||||||||||||||||||||||||||||
| CVSS v3 Severity: | 6.1 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N) 5.3 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N/E:U/RL:O/RC:C)
6.4 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N/E:U/RL:O/RC:C)
| ||||||||||||||||||||||||||||||||||||
| CVSS v2 Severity: | 5.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N)
| ||||||||||||||||||||||||||||||||||||
| Vulnerability Type: | CWE-601 | ||||||||||||||||||||||||||||||||||||
| Vulnerability Consequences: | Gain Access | ||||||||||||||||||||||||||||||||||||
| References: | Source: MITRE Type: CNA CVE-2018-11408 Source: XF Type: UNKNOWN symfony-cve201811408-open-redirect(144826) Source: MLIST Type: Third Party Advisory [debian-lts-announce] 20190310 [SECURITY] [DLA 1707-1] symfony security update Source: FEDORA Type: Third Party Advisory FEDORA-2018-eba0006df2 Source: FEDORA Type: Third Party Advisory FEDORA-2018-96d770ddc9 Source: FEDORA Type: Third Party Advisory FEDORA-2018-ba0b683c10 Source: CCN Type: Symfony blog, May 25, 2018 CVE-2018-11408: Open redirect vulnerability on security handlers Source: CONFIRM Type: Vendor Advisory https://symfony.com/blog/cve-2018-11408-open-redirect-vulnerability-on-security-handlers | ||||||||||||||||||||||||||||||||||||
| Vulnerable Configuration: | Configuration 1: Configuration 2: Denotes that component is vulnerable | ||||||||||||||||||||||||||||||||||||
| Oval Definitions | |||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||
| BACK | |||||||||||||||||||||||||||||||||||||