CVE-2013-4752
published 2020-01-02CVE-2013-4752: Symfony 2.0.X before 2.0.24, 2.1.X before 2.1.12, 2.2.X before 2.2.5, and 2.3.X before 2.3.3 have an issue in the HttpFoundation component. The Host header can…
PriorityP431medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
2.31%
81.6th percentile
Symfony 2.0.X before 2.0.24, 2.1.X before 2.1.12, 2.2.X before 2.2.5, and 2.3.X before 2.3.3 have an issue in the HttpFoundation component. The Host header can be manipulated by an attacker when the framework is generating an absolute URL. A remote attacker could exploit this vulnerability to inject malicious content into the Web application page and conduct various attacks.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| sensiolabs | symfony | >= 2.0.0 < 2.0.24 | 2.0.24 |
| sensiolabs | symfony | >= 2.1.0 < 2.1.12 | 2.1.12 |
| sensiolabs | symfony | >= 2.2.0 < 2.2.5 | 2.2.5 |
| sensiolabs | symfony | >= 2.3.0 < 2.3.3 | 2.3.3 |
| symfony | http-foundation | >= 2.0.0 < 2.0.24 | 2.0.24 |
| symfony | http-foundation | >= 2.1.0 < 2.1.12 | 2.1.12 |
| symfony | http-foundation | >= 2.2.0 < 2.2.5 | 2.2.5 |
| symfony | http-foundation | >= 2.3.0 < 2.3.3 | 2.3.3 |
| symfony | symfony | >= 2.0.0 < 2.0.24 | 2.0.24 |
| symfony | symfony | >= 2.1.0 < 2.1.12 | 2.1.12 |
| symfony | symfony | >= 2.2.0 < 2.2.5 | 2.2.5 |
| symfony | symfony | >= 2.3.0 < 2.3.3 | 2.3.3 |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Symfony Host Header Injection vulnerability in the HttpFoundation component
osv·2022-05-05
CVE-2013-4752 [MEDIUM] Symfony Host Header Injection vulnerability in the HttpFoundation component
Symfony Host Header Injection vulnerability in the HttpFoundation component
Symfony 2.0.X before 2.0.24, 2.1.X before 2.1.12, 2.2.X before 2.2.5, and 2.3.X before 2.3.3 have an issue in the HttpFoundation component. The Host header can be manipulated by an attacker when the framework is generating an absolute URL. A remote attacker could exploit this vulnerability to inject malicious content into the Web application page and conduct various attacks.
GHSA
Symfony Host Header Injection vulnerability in the HttpFoundation component
ghsa·2022-05-05
CVE-2013-4752 [MEDIUM] CWE-79 Symfony Host Header Injection vulnerability in the HttpFoundation component
Symfony Host Header Injection vulnerability in the HttpFoundation component
Symfony 2.0.X before 2.0.24, 2.1.X before 2.1.12, 2.2.X before 2.2.5, and 2.3.X before 2.3.3 have an issue in the HttpFoundation component. The Host header can be manipulated by an attacker when the framework is generating an absolute URL. A remote attacker could exploit this vulnerability to inject malicious content into the Web application page and conduct various attacks.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-4752 php-symfony2-HttpFoundation: Request::getHost() poisioning
bugzilla·2013-08-09·CVSS 6.1
CVE-2013-4752 [MEDIUM] CVE-2013-4752 php-symfony2-HttpFoundation: Request::getHost() poisioning
CVE-2013-4752 php-symfony2-HttpFoundation: Request::getHost() poisioning
As noted from [1]:
CVE-2013-4752: Request::getHost() poisoning
Affected versions
All 2.0.X, 2.1.X, 2.2.X, and 2.3.X versions of the HttpFoundation component are affected by this issue.
Description:
As the $_SERVER['HOST'] content is an input coming from the user, it can be manipulated and cannot be trusted. In the recent months, a lot of different attacks have been discovered relying on inconsistencies between the handling of the Host header by various software (web servers, reverse proxies, web frameworks, ...). Basically, everytime the framework is generating an absolute URL (when sending an email to reset a password for instance), the host might have been manipulated by an attacker. And depending on the confi
Bugzilla
CVE-2013-4752 php-symfony2-HttpFoundation: Request::getHost() poisioning [fedora-all]
bugzilla·2013-08-09·CVSS 6.1
CVE-2013-4752 [MEDIUM] CVE-2013-4752 php-symfony2-HttpFoundation: Request::getHost() poisioning [fedora-all]
CVE-2013-4752 php-symfony2-HttpFoundation: Request::getHost() poisioning [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this i
Bugzilla
CVE-2013-4752 php-symfony2-HttpFoundation: Request::getHost() poisioning [epel-6]
bugzilla·2013-08-09·CVSS 6.1
CVE-2013-4752 [MEDIUM] CVE-2013-4752 php-symfony2-HttpFoundation: Request::getHost() poisioning [epel-6]
CVE-2013-4752 php-symfony2-HttpFoundation: Request::getHost() poisioning [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
epel-6 tracking bu
http://lists.fedoraproject.org/pipermail/package-announce/2013-August/114450.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-August/114461.htmlhttp://symfony.com/blog/security-releases-symfony-2-0-24-2-1-12-2-2-5-and-2-3-3-releasedhttp://www.securityfocus.com/bid/61715https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2013-4752https://exchange.xforce.ibmcloud.com/vulnerabilities/86365https://exchange.xforce.ibmcloud.com/vulnerabilities/86366https://exchange.xforce.ibmcloud.com/vulnerabilities/86367https://exchange.xforce.ibmcloud.com/vulnerabilities/86368https://exchange.xforce.ibmcloud.com/vulnerabilities/86369https://exchange.xforce.ibmcloud.com/vulnerabilities/86370https://exchange.xforce.ibmcloud.com/vulnerabilities/86371https://exchange.xforce.ibmcloud.com/vulnerabilities/86372https://exchange.xforce.ibmcloud.com/vulnerabilities/86373https://exchange.xforce.ibmcloud.com/vulnerabilities/86374http://lists.fedoraproject.org/pipermail/package-announce/2013-August/114450.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-August/114461.htmlhttp://symfony.com/blog/security-releases-symfony-2-0-24-2-1-12-2-2-5-and-2-3-3-releasedhttp://www.securityfocus.com/bid/61715https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2013-4752https://exchange.xforce.ibmcloud.com/vulnerabilities/86365https://exchange.xforce.ibmcloud.com/vulnerabilities/86366https://exchange.xforce.ibmcloud.com/vulnerabilities/86367https://exchange.xforce.ibmcloud.com/vulnerabilities/86368https://exchange.xforce.ibmcloud.com/vulnerabilities/86369https://exchange.xforce.ibmcloud.com/vulnerabilities/86370https://exchange.xforce.ibmcloud.com/vulnerabilities/86371https://exchange.xforce.ibmcloud.com/vulnerabilities/86372https://exchange.xforce.ibmcloud.com/vulnerabilities/86373https://exchange.xforce.ibmcloud.com/vulnerabilities/86374
2020-01-02
Published