CVE-2019-18888Argument Injection in Http-foundation

Severity
7.5HIGHNVD
EPSS
2.3%
top 15.21%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 21
Latest updateDec 2

Description

An issue was discovered in Symfony 2.8.0 through 2.8.50, 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4.3.7. If an application passes unvalidated user input as the file for which MIME type validation should occur, then arbitrary arguments are passed to the underlying file command. This is related to symfony/http-foundation (and symfony/mime in 4.3.x).

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages5 packages

Packagistsymfony/mime4.3.04.3.8
Packagistsymfony/http-foundation2.0.02.8.52+3
Packagistsymfony/symfony2.0.02.8.52+3
Debiansymfony/symfony< 4.3.8+dfsg-1+3
NVDsensiolabs/symfony2.8.02.8.50+3

Also affects: Fedora 30, 31

🔴Vulnerability Details

4
GHSA
Argument injection in a MimeTypeGuesser in Symfony2019-12-02
OSV
Argument injection in a MimeTypeGuesser in Symfony2019-12-02
OSV
CVE-2019-18888: An issue was discovered in Symfony 22019-11-21
CVEList
CVE-2019-18888: An issue was discovered in Symfony 22019-11-21

📋Vendor Advisories

1
Debian
CVE-2019-18888: symfony - An issue was discovered in Symfony 2.8.0 through 2.8.50, 3.4.0 through 3.4.34, 4...2019
CVE-2019-18888 — Argument Injection in Http-foundation | cvebase