CVE-2018-11408Open Redirect in Symfony

CWE-601Open Redirect12 documents6 sources
Severity
6.1MEDIUMNVD
EPSS
0.3%
top 46.03%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 13
Latest updateMay 14

Description

The security handlers in the Security component in Symfony in 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x before 4.0.11 have an Open redirect vulnerability when security.http_utils is inlined by a container. NOTE: this issue exists because of an incomplete fix for CVE-2017-16652.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages4 packages

Packagistsymfony/security-bundle2.7.02.7.48+4
Packagistsymfony/symfony2.7.02.7.48+4
NVDsensiolabs/symfony2.7.02.7.48+4
Debiansymfony/symfony< 3.4.12+dfsg-1+3

Also affects: Debian Linux 8.0

🔴Vulnerability Details

4
OSV
Symfony Open Redirect2022-05-14
GHSA
Symfony Open Redirect2022-05-14
CVEList
CVE-2018-11408: The security handlers in the Security component in Symfony in 22018-06-13
OSV
CVE-2018-11408: The security handlers in the Security component in Symfony in 22018-06-13

📋Vendor Advisories

1
Debian
CVE-2018-11408: symfony - The security handlers in the Security component in Symfony in 2.7.x before 2.7.4...2018

💬Community

6
Bugzilla
CVE-2017-16652 CVE-2018-11385 CVE-2018-11386 CVE-2018-11406 CVE-2018-11407 CVE-2018-11408 php-symfony4: php-symfony: Multiple flaws [fedora-all]2018-06-15
Bugzilla
CVE-2017-16652 CVE-2018-11385 CVE-2018-11386 CVE-2018-11406 CVE-2018-11407 CVE-2018-11408 php-symfony-symfony: php-symfony: Multiple flaws [epel-6]2018-06-15
Bugzilla
CVE-2017-16652 CVE-2018-11385 CVE-2018-11386 CVE-2018-11406 CVE-2018-11407 CVE-2018-11408 php-symfony3: php-symfony: Multiple flaws [fedora-all]2018-06-15
Bugzilla
CVE-2017-16652 CVE-2018-11385 CVE-2018-11386 CVE-2018-11406 CVE-2018-11407 CVE-2018-11408 php-symfony: Multiple flaws2018-06-14
Bugzilla
CVE-2017-16652 CVE-2018-11385 CVE-2018-11386 CVE-2018-11406 CVE-2018-11407 CVE-2018-11408 php-symfony: Multiple flaws [fedora-all]2018-06-14
CVE-2018-11408 — Open Redirect in Sensiolabs Symfony | cvebase