cbcvebase.
CVE-2020-15094
published 2020-09-02

CVE-2020-15094: In Symfony before versions 4.4.13 and 5.1.5, the CachingHttpClient class from the HttpClient Symfony component relies on the HttpCache class to handle…

PriorityP358high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
3.04%
86.1th percentile
In Symfony before versions 4.4.13 and 5.1.5, the CachingHttpClient class from the HttpClient Symfony component relies on the HttpCache class to handle requests. HttpCache uses internal headers like X-Body-Eval and X-Body-File to control the restoration of cached responses. The class was initially written with surrogate caching and ESI support in mind (all HTTP calls come from a trusted backend in that scenario). But when used by CachingHttpClient and if an attacker can control the response for a request being made by the CachingHttpClient, remote code execution is possible. This has been fixed in versions 4.4.13 and 5.1.5.

Affected

17 ranges
VendorProductVersion rangeFixed in
debiansymfony< symfony 4.4.13+dfsg-1 (bookworm)symfony 4.4.13+dfsg-1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
sensiolabshttpclient>= 4.4.0 < 4.4.134.4.13
sensiolabshttpclient>= 5.1.0 < 5.1.55.1.5
sensiolabssymfony>= 4.4.0 < 4.4.134.4.13
sensiolabssymfony>= 5.1.0 < 5.1.55.1.5
symfonyhttp-kernel>= 4.3.0 < 4.4.134.4.13
symfonyhttp-kernel>= 5.0.0 < 5.1.55.1.5
symfonysymfony
symfonysymfony
symfonysymfony>= 0 < 4.4.13+dfsg-14.4.13+dfsg-1
symfonysymfony>= 0 < 4.4.13+dfsg-14.4.13+dfsg-1
symfonysymfony>= 0 < 4.4.13+dfsg-14.4.13+dfsg-1
symfonysymfony>= 0 < 4.4.13+dfsg-14.4.13+dfsg-1
symfonysymfony>= 4.3.0 < 4.4.134.4.13
symfonysymfony>= 5.0.0 < 5.1.55.1.5

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.0HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.