| Vulnerability Name: | CVE-2019-11325 (CCN-172182) | ||||||||||||||||
| Assigned: | 2019-11-13 | ||||||||||||||||
| Published: | 2019-11-13 | ||||||||||||||||
| Updated: | 2020-08-24 | ||||||||||||||||
| Summary: | An issue was discovered in Symfony before 4.2.12 and 4.3.x before 4.3.8. The VarExport component incorrectly escapes strings, allowing some specially crafted ones to escalate to execution of arbitrary PHP code. This is related to symfony/var-exporter. | ||||||||||||||||
| CVSS v3 Severity: | 9.8 Critical (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) 8.5 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
8.5 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
| ||||||||||||||||
| CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||||||||||
| Vulnerability Type: | CWE-116 | ||||||||||||||||
| Vulnerability Consequences: | Gain Access | ||||||||||||||||
| References: | Source: MITRE Type: CNA CVE-2019-11325 Source: XF Type: UNKNOWN symfony-cve201911325-code-exec(172182) Source: CONFIRM Type: Release Notes, Third Party Advisory https://github.com/symfony/symfony/releases/tag/v4.3.8 Source: MISC Type: Patch, Third Party Advisory https://github.com/symfony/var-exporter/compare/d8bf442...57e00f3 Source: CCN Type: Symfony Web site symfony Source: CCN Type: Symfony blog, November 13, 2019 CVE-2019-11325: Fix escaping of strings in VarExporter Source: CONFIRM Type: Vendor Advisory https://symfony.com/blog/cve-2019-11325-fix-escaping-of-strings-in-varexporter Source: CONFIRM Type: Release Notes, Vendor Advisory https://symfony.com/blog/symfony-4-3-8-released | ||||||||||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||
| Oval Definitions | |||||||||||||||||
| |||||||||||||||||
| BACK | |||||||||||||||||