CVE-2017-16654Path Traversal in Intl

CWE-22Path Traversal11 documents6 sources
Severity
7.5HIGHNVD
EPSS
0.5%
top 32.24%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 6
Latest updateMay 14

Description

An issue was discovered in Symfony before 2.7.38, 2.8.31, 3.2.14, 3.3.13, 3.4-BETA5, and 4.0-BETA5. The Intl component includes various bundle readers that are used to read resource bundles from the local filesystem. The read() methods of these classes use a path and a locale to determine the language bundle to retrieve. The locale argument value is commonly retrieved from untrusted user input (like a URL parameter). An attacker can use this argument to navigate to arbitrary directories via the

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages4 packages

Packagistsymfony/intl2.7.02.7.38+3
Packagistsymfony/symfony2.7.02.7.38+3
Debiansymfony/symfony< 3.4.0+dfsg-1+3
NVDsensiolabs/symfony2.7.02.7.37+3

Also affects: Debian Linux 8.0, 9.0

🔴Vulnerability Details

4
OSV
Symfony Directory Traversal2022-05-14
GHSA
Symfony Directory Traversal2022-05-14
OSV
CVE-2017-16654: An issue was discovered in Symfony before 22018-08-06
CVEList
CVE-2017-16654: An issue was discovered in Symfony before 22018-08-06

📋Vendor Advisories

1
Debian
CVE-2017-16654: symfony - An issue was discovered in Symfony before 2.7.38, 2.8.31, 3.2.14, 3.3.13, 3.4-BE...2017

💬Community

5
Bugzilla
CVE-2017-16654 php-symfony: Directory Traversal in the Intl component2018-08-22
Bugzilla
CVE-2017-16654 php-symfony: Directory Traversal in the Intl component [epel-7]2018-08-22
Bugzilla
CVE-2017-16654 php-symfony: Directory Traversal in the Intl component [fedora-27]2018-08-22
Bugzilla
CVE-2017-16654 php-symfony4: php-symfony: Directory Traversal in the Intl component [fedora-all]2018-08-22
Bugzilla
CVE-2017-16654 php-symfony3: php-symfony: Directory Traversal in the Intl component [fedora-28]2018-08-22
CVE-2017-16654 — Path Traversal in Symfony Intl | cvebase