Vulnerability Name: | CVE-2019-18887 (CCN-171861) | ||||||||||||||||
Assigned: | 2019-11-13 | ||||||||||||||||
Published: | 2019-11-13 | ||||||||||||||||
Updated: | 2020-08-24 | ||||||||||||||||
Summary: | An issue was discovered in Symfony 2.8.0 through 2.8.50, 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4.3.7. The UriSigner was subject to timing attacks. This is related to symfony/http-kernel. | ||||||||||||||||
CVSS v3 Severity: | 8.1 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H) 7.1 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
6.5 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C)
| ||||||||||||||||
CVSS v2 Severity: | 6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P)
| ||||||||||||||||
Vulnerability Type: | CWE-203 | ||||||||||||||||
Vulnerability Consequences: | Obtain Information | ||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2019-18887 Source: XF Type: UNKNOWN symfony-cve201918887-info-disc(171861) Source: CCN Type: symfony GIT Repository [HttpKernel] Use constant time comparison in UriSigner Source: CONFIRM Type: Release Notes https://github.com/symfony/symfony/releases/tag/v4.3.8 Source: FEDORA Type: Third Party Advisory FEDORA-2019-9c2ad3b018 Source: FEDORA Type: Third Party Advisory FEDORA-2019-8b0ba02338 Source: FEDORA Type: Third Party Advisory FEDORA-2019-5ae4fd9203 Source: CCN Type: BugTraq Mailing List, Mon, 18 Nov 2019 22:04:18 +0000 [SECURITY] [DSA 4573-1] symfony security update Source: CONFIRM Type: Vendor Advisory https://symfony.com/blog/cve-2019-18887-use-constant-time-comparison-in-urisigner Source: CONFIRM Type: Release Notes https://symfony.com/blog/symfony-4-3-8-released Source: CCN Type: WhiteSource Vulnerability Database CVE-2019-18887 | ||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration CCN 1: ![]() | ||||||||||||||||
Oval Definitions | |||||||||||||||||
| |||||||||||||||||
BACK |