Arbitrary Code Injection Affecting symfony/symfony package, versions >=2.3.0, <2.3.27 >=2.6.0, <2.6.6 >=2.1.0, <2.2.0 >=2.4.0, <2.5.0 >=2.5.0, <2.5.11 >=2.2.0, <2.3.0 >=2, <2.1.0
Threat Intelligence
EPSS
0.53% (78th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-PHP-SYMFONYSYMFONY-70215
- published 1 Apr 2015
- disclosed 1 Apr 2015
- credit Unknown
How to fix?
Upgrade symfony/symfony
to version 2.3.27, 2.6.6, 2.2.0, 2.5.0, 2.5.11, 2.3.0, 2.1.0 or higher.
Overview
Affected versions of symfony/symfony
are vulnerable to Arbitrary Code Injection.
Eval injection vulnerability in the HttpCache class in HttpKernel in Symfony 2.x before 2.3.27, 2.4.x and 2.5.x before 2.5.11, and 2.6.x before 2.6.6 allows remote attackers to execute arbitrary PHP code via a language="php"
attribute of a SCRIPT element.
References
CVSS Scores
version 3.1