CVE-2019-18887Observable Discrepancy in Http-kernel

Severity
8.1HIGHNVD
EPSS
0.8%
top 25.71%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 21
Latest updateMar 26

Description

An issue was discovered in Symfony 2.8.0 through 2.8.50, 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4.3.7. The UriSigner was subject to timing attacks. This is related to symfony/http-kernel.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 2.2 | Impact: 5.9

Affected Packages4 packages

Packagistsymfony/http-kernel2.2.02.8.52+3
Packagistsymfony/symfony2.2.02.8.52+3
Debiansymfony/symfony< 4.3.8+dfsg-1+3
NVDsensiolabs/symfony2.8.02.8.50+3

Also affects: Fedora 30, 31

🔴Vulnerability Details

4
GHSA
Symfony Http-Kernel has non-constant time comparison in UriSigner2022-03-26
OSV
Symfony Http-Kernel has non-constant time comparison in UriSigner2022-03-26
CVEList
CVE-2019-18887: An issue was discovered in Symfony 22019-11-21
OSV
CVE-2019-18887: An issue was discovered in Symfony 22019-11-21

📋Vendor Advisories

1
Debian
CVE-2019-18887: symfony - An issue was discovered in Symfony 2.8.0 through 2.8.50, 3.4.0 through 3.4.34, 4...2019
CVE-2019-18887 — Observable Discrepancy in Http-kernel | cvebase