CVE-2017-16790Improper Input Validation in Form

Severity
6.5MEDIUMNVD
EPSS
0.7%
top 28.26%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 6
Latest updateMay 14

Description

An issue was discovered in Symfony before 2.7.38, 2.8.31, 3.2.14, 3.3.13, 3.4-BETA5, and 4.0-BETA5. When a form is submitted by the user, the request handler classes of the Form component merge POST data and uploaded files data into one array. This big array forms the data that are then bound to the form. At this stage there is no difference anymore between submitted POST data and uploaded files. A user can send a crafted HTTP request where the value of a "FileType" is sent as normal POST data t

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages4 packages

Packagistsymfony/form2.7.02.7.38+3
Packagistsymfony/symfony2.7.02.7.38+3
Debiansymfony/symfony< 3.4.0+dfsg-1+3
NVDsensiolabs/symfony2.7.02.7.37+3

Also affects: Debian Linux 9.0

Patches

🔴Vulnerability Details

5
GHSA
Symfony SSRF Vulnerability via Form Component2022-05-14
OSV
Symfony SSRF Vulnerability via Form Component2022-05-14
OSV
libbson vulnerabilities2021-03-15
CVEList
CVE-2017-16790: An issue was discovered in Symfony before 22018-08-06
OSV
CVE-2017-16790: An issue was discovered in Symfony before 22018-08-06

📋Vendor Advisories

1
Debian
CVE-2017-16790: symfony - An issue was discovered in Symfony before 2.7.38, 2.8.31, 3.2.14, 3.3.13, 3.4-BE...2017

💬Community

5
Bugzilla
CVE-2017-16790 php-symfony4: php-symfony: Information Exposure due to an improper check of FileType on submitted data [fedora-all]2018-08-22
Bugzilla
CVE-2017-16790 php-symfony: Information Exposure due to an improper check of FileType on submitted data [fedora-27]2018-08-22
Bugzilla
CVE-2017-16790 php-symfony: Information Exposure due to an improper check of FileType on submitted data [epel-7]2018-08-22
Bugzilla
CVE-2017-16790 php-symfony: Information Exposure due to an improper check of FileType on submitted data2018-08-22
Bugzilla
CVE-2017-16790 php-symfony3: php-symfony: Information Exposure due to an improper check of FileType on submitted data [fedora-28]2018-08-22
CVE-2017-16790 — Improper Input Validation in Form | cvebase