cbcvebase.
CVE-2020-5255
published 2020-03-30

CVE-2020-5255: In Symfony before versions 4.4.7 and 5.0.7, when a `Response` does not contain a `Content-Type` header, affected versions of Symfony can fallback to the format…

PriorityP420medium4.3CVSS 3.1
AVNACLPRLUINSUCNINAL
EPSS
1.30%
67.2th percentile
In Symfony before versions 4.4.7 and 5.0.7, when a `Response` does not contain a `Content-Type` header, affected versions of Symfony can fallback to the format defined in the `Accept` header of the request, leading to a possible mismatch between the response's content and `Content-Type` header. When the response is cached, this can prevent the use of the website by other users. This has been patched in versions 4.4.7 and 5.0.7.

Affected

13 ranges
VendorProductVersion rangeFixed in
debiansymfony< symfony 4.4.8-1 (bookworm)symfony 4.4.8-1 (bookworm)
sensiolabssymfony>= 4.4.0 < 4.4.74.4.7
sensiolabssymfony>= 5.0.0 < 5.0.75.0.7
symfonyhttp-foundation>= 4.4.0 < 4.4.74.4.7
symfonyhttp-foundation>= 5.0.0 < 5.0.75.0.7
symfonysymfony
symfonysymfony
symfonysymfony>= 0 < 4.4.8-14.4.8-1
symfonysymfony>= 0 < 4.4.8-14.4.8-1
symfonysymfony>= 0 < 4.4.8-14.4.8-1
symfonysymfony>= 0 < 4.4.8-14.4.8-1
symfonysymfony>= 4.4.0 < 4.4.74.4.7
symfonysymfony>= 5.0.0 < 5.0.75.0.7

CVSS provenance

nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
osv4.3MEDIUM
vendor_debian2.6LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.