Access Restriction Bypass Affecting symfony/symfony package, versions >=2.1.0, <2.1.4 >=2.0.0, <2.0.19
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-PHP-SYMFONYSYMFONY-70202
- published 27 Nov 2012
- disclosed 27 Nov 2012
- credit Damien Tournoud
How to fix?
Upgrade symfony/symfony
to version 2.1.4, 2.0.19 or higher.
Overview
symfony/symfony is a PHP framework for web applications and a set of reusable PHP components.
Affected versions of this package are vulnerable to Access Restriction Bypass in the Request::getClientIp()
method when the trust proxy mode is enabled (Request::trustProxyData()
).
An application is vulnerable if it uses the client IP address as returned by the Request::getClientIp()
method for sensitive decisions like IP based access control.
References
CVSS Scores
version 3.1