CVE Database
/

CVE-2015-4050

Back to search

CVE-2015-4050

Published: Jun 2, 2015

Modified: Aug 6, 2024

PUBLISHED

Description

FragmentListener in the HttpKernel component in Symfony 2.3.19 through 2.3.28, 2.4.9 through 2.4.10, 2.5.4 through 2.5.11, and 2.6.0 through 2.6.7, when ESI or SSI support enabled, does not check if the _controller attribute is set, which allows remote attackers to bypass URL signing and security rules by including (1) no hash or (2) an invalid hash in a request to /_fragment.

VendorProductVersions

n/a

n/a

affected
n/a

References

FEDORA-2015-9039
vendor-advisory
x_refsource_FEDORA
DSA-3276
vendor-advisory
x_refsource_DEBIAN
FEDORA-2015-9034
vendor-advisory
x_refsource_FEDORA
FEDORA-2015-9025
vendor-advisory
x_refsource_FEDORA
74928
vdb-entry
x_refsource_BID

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now