CVE-2018-19790Open Redirect in Symfony

CWE-601Open Redirect11 documents6 sources
Severity
6.1MEDIUMNVD
EPSS
0.4%
top 36.46%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 18
Latest updateMay 14

Description

An open redirect was discovered in Symfony 2.7.x before 2.7.50, 2.8.x before 2.8.49, 3.x before 3.4.20, 4.0.x before 4.0.15, 4.1.x before 4.1.9 and 4.2.x before 4.2.1. By using backslashes in the `_failure_path` input field of login forms, an attacker can work around the redirection target restrictions and effectively redirect the user to any domain after login.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages5 packages

Packagistsymfony/symfony2.7.382.7.50+4
Packagistsymfony/security2.7.382.7.50+5
NVDsensiolabs/symfony2.7.02.7.50+5
Packagistsymfony/security-http2.7.382.7.50+5
Debiansymfony/symfony< 3.4.20+dfsg-1+3

Also affects: Debian Linux 8.0, Fedora 28

Patches

🔴Vulnerability Details

4
GHSA
Symfony Open Redirect2022-05-14
OSV
Symfony Open Redirect2022-05-14
OSV
CVE-2018-19790: An open redirect was discovered in Symfony 22018-12-18
CVEList
CVE-2018-19790: An open redirect was discovered in Symfony 22018-12-18

📋Vendor Advisories

1
Debian
CVE-2018-19790: symfony - An open redirect was discovered in Symfony 2.7.x before 2.7.50, 2.8.x before 2.8...2018

💬Community

5
Bugzilla
CVE-2019-10909 CVE-2019-10910 CVE-2019-10912 CVE-2019-10913 CVE-2018-19790 CVE-2018-19789 php-symfony: Multiple vulnerabilities fixed in symfony 2.8.7 [epel-all]2019-06-12
Bugzilla
CVE-2019-10909 CVE-2019-10910 CVE-2019-10912 CVE-2019-10913 CVE-2018-19790 CVE-2018-19789 php-symfony: Multiple vulnerabilities fixed in symfony 2.8.72019-06-12
Bugzilla
CVE-2019-10909 CVE-2019-10910 CVE-2019-10912 CVE-2019-10913 CVE-2018-19790 CVE-2018-19789 php-symfony: Multiple vulnerabilities fixed in symfony 2.8.7 [fedora-all]2019-06-12
Bugzilla
CVE-2019-10909 CVE-2019-10910 CVE-2019-10912 CVE-2019-10913 CVE-2018-19790 CVE-2018-19789 php-symfony4: php-symfony: Multiple vulnerabilities fixed in symfony 2.8.7 [fedora-all]2019-06-12
Bugzilla
CVE-2019-10909 CVE-2019-10910 CVE-2019-10912 CVE-2019-10913 CVE-2018-19790 CVE-2018-19789 php-symfony3: php-symfony: Multiple vulnerabilities fixed in symfony 2.8.7 [fedora-all]2019-06-12
CVE-2018-19790 — Open Redirect in Sensiolabs Symfony | cvebase