CVE-2019-18889Code Injection in Cache

CWE-94Code Injection6 documents5 sources
Severity
9.8CRITICALNVD
EPSS
2.6%
top 14.48%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 21
Latest updateDec 2

Description

An issue was discovered in Symfony 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4.3.7. Serializing certain cache adapter interfaces could result in remote code injection. This is related to symfony/cache.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages4 packages

Packagistsymfony/cache3.1.03.4.35+2
Packagistsymfony/symfony3.1.03.4.35+2
Debiansymfony/symfony< 4.3.8+dfsg-1+3
NVDsensiolabs/symfony3.4.03.4.34+2

Also affects: Fedora 31

🔴Vulnerability Details

4
GHSA
Symfony Unsafe Cache Serialization Could Enable RCE2019-12-02
OSV
Symfony Unsafe Cache Serialization Could Enable RCE2019-12-02
OSV
CVE-2019-18889: An issue was discovered in Symfony 32019-11-21
CVEList
CVE-2019-18889: An issue was discovered in Symfony 32019-11-21

📋Vendor Advisories

1
Debian
CVE-2019-18889: symfony - An issue was discovered in Symfony 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, a...2019
CVE-2019-18889 — Code Injection in Symfony Cache | cvebase