Back to search
CVE-2015-4050
Published: Jun 2, 2015
Modified: Aug 6, 2024
PUBLISHED
Description
FragmentListener in the HttpKernel component in Symfony 2.3.19 through 2.3.28, 2.4.9 through 2.4.10, 2.5.4 through 2.5.11, and 2.6.0 through 2.6.7, when ESI or SSI support enabled, does not check if the _controller attribute is set, which allows remote attackers to bypass URL signing and security rules by including (1) no hash or (2) an invalid hash in a request to /_fragment.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
http://symfony.com/blog/cve-2015-4050-esi-unauthorized-access
x_refsource_CONFIRM
FEDORA-2015-9039
vendor-advisory
x_refsource_FEDORA
DSA-3276
vendor-advisory
x_refsource_DEBIAN
FEDORA-2015-9034
vendor-advisory
x_refsource_FEDORA
FEDORA-2015-9025
vendor-advisory
x_refsource_FEDORA
74928
vdb-entry
x_refsource_BID
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now