Debian Symfony vulnerabilities
52 known vulnerabilities affecting debian/symfony.
Total CVEs
52
CISA KEV
0
Public exploits
3
Exploited in wild
0
Severity breakdown
CRITICAL6HIGH16MEDIUM20LOW9UNKNOWN1
Vulnerabilities
Page 1 of 3
CVE-2024-50340P2HIGHCVSS 7.3PoCfixed in symfony 5.4.23+dfsg-1+deb12u3 (bookworm)2024
CVE-2024-50340 [HIGH] CVE-2024-50340: symfony - symfony/runtime is a module for the Symphony PHP framework which enables decoupl...
symfony/runtime is a module for the Symphony PHP framework which enables decoupling PHP applications from global state. When the `register_argv_argc` php directive is set to `on` , and users call any URL with a special crafted query string, they are able to change the environment or debug mode used by the kernel when handling the request. As of versions 5.4.46, 6.4.
debian
CVE-2025-64500P3HIGHCVSS 7.3PoCfixed in symfony 5.4.23+dfsg-1+deb12u5 (bookworm)2025
CVE-2025-64500 [HIGH] CVE-2025-64500: symfony - Symfony is a PHP framework for web and console applications and a set of reusabl...
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Symfony's HttpFoundation component defines an object-oriented layer for the HTTP specification. Starting in version 2.0.0 and prior to version 5.4.50, 6.4.29, and 7.3.7, the `Request` class improperly interprets some `PATH_INFO` in a way that leads to representing some
debian
CVE-2019-18889P2CRITICALCVSS 9.8fixed in symfony 4.3.8+dfsg-1 (bookworm)2019
CVE-2019-18889 [CRITICAL] CVE-2019-18889: symfony - An issue was discovered in Symfony 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, a...
An issue was discovered in Symfony 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4.3.7. Serializing certain cache adapter interfaces could result in remote code injection. This is related to symfony/cache.
Scope: local
bookworm: resolved (fixed in 4.3.8+dfsg-1)
bullseye: resolved (fixed in 4.3.8+dfsg-1)
forky: resolved (fixed in 4.3.8+dfsg-1)
sid
debian
CVE-2018-14773P3MEDIUMCVSS 6.5fixed in symfony 3.4.14+dfsg-1 (bookworm)2018
CVE-2018-14773 [MEDIUM] CVE-2018-14773: symfony - An issue was discovered in Http Foundation in Symfony 2.7.0 through 2.7.48, 2.8....
An issue was discovered in Http Foundation in Symfony 2.7.0 through 2.7.48, 2.8.0 through 2.8.43, 3.3.0 through 3.3.17, 3.4.0 through 3.4.13, 4.0.0 through 4.0.13, and 4.1.0 through 4.1.2. It arises from support for a (legacy) IIS header that lets users override the path in the request URL via the X-Original-URL or X-Rewrite-URL HTTP request header. These headers
debian
CVE-2019-10910P2CRITICALCVSS 9.8fixed in symfony 3.4.22+dfsg-2 (bookworm)2019
CVE-2019-10910 [CRITICAL] CVE-2019-10910: symfony - In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1...
In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, when service ids allow user input, this could allow for SQL Injection and remote code execution. This is related to symfony/dependency-injection.
Scope: local
bookworm: resolved (fixed in 3.4.22+dfsg-2)
bullseye: resolved (fixed in 3.4.22+dfsg-2)
forky: r
debian
CVE-2016-2403P3CRITICALCVSS 9.8fixed in symfony 2.8.6+dfsg-1 (bookworm)2016
CVE-2016-2403 [CRITICAL] CVE-2016-2403: symfony - Symfony before 2.8.6 and 3.x before 3.0.6 allows remote attackers to bypass auth...
Symfony before 2.8.6 and 3.x before 3.0.6 allows remote attackers to bypass authentication by logging in with an empty password and valid username, which triggers an unauthenticated bind.
Scope: local
bookworm: resolved (fixed in 2.8.6+dfsg-1)
bullseye: resolved (fixed in 2.8.6+dfsg-1)
forky: resolved (fixed in 2.8.6+dfsg-1)
sid: resolved (fixed in 2.8.6+dfsg-1)
t
debian
CVE-2020-15094P3HIGHCVSS 8.0fixed in symfony 4.4.13+dfsg-1 (bookworm)2020
CVE-2020-15094 [HIGH] CVE-2020-15094: symfony - In Symfony before versions 4.4.13 and 5.1.5, the CachingHttpClient class from th...
In Symfony before versions 4.4.13 and 5.1.5, the CachingHttpClient class from the HttpClient Symfony component relies on the HttpCache class to handle requests. HttpCache uses internal headers like X-Body-Eval and X-Body-File to control the restoration of cached responses. The class was initially written with surrogate caching and ESI support in mind (all HTTP calls
debian
CVE-2015-4050P3MEDIUMCVSS 4.3PoCfixed in symfony 2.7.0~beta2+dfsg-2 (bookworm)2015
CVE-2015-4050 [MEDIUM] CVE-2015-4050: symfony - FragmentListener in the HttpKernel component in Symfony 2.3.19 through 2.3.28, 2...
FragmentListener in the HttpKernel component in Symfony 2.3.19 through 2.3.28, 2.4.9 through 2.4.10, 2.5.4 through 2.5.11, and 2.6.0 through 2.6.7, when ESI or SSI support enabled, does not check if the _controller attribute is set, which allows remote attackers to bypass URL signing and security rules by including (1) no hash or (2) an invalid hash in a request to
debian
CVE-2019-11325P3CRITICALCVSS 9.8fixed in symfony 4.3.8+dfsg-1 (bookworm)2019
CVE-2019-11325 [CRITICAL] CVE-2019-11325: symfony - An issue was discovered in Symfony before 4.2.12 and 4.3.x before 4.3.8. The Var...
An issue was discovered in Symfony before 4.2.12 and 4.3.x before 4.3.8. The VarExport component incorrectly escapes strings, allowing some specially crafted ones to escalate to execution of arbitrary PHP code. This is related to symfony/var-exporter.
Scope: local
bookworm: resolved (fixed in 4.3.8+dfsg-1)
bullseye: resolved (fixed in 4.3.8+dfsg-1)
forky: resolv
debian
CVE-2018-11407P3CRITICALCVSS 9.8fixed in symfony 3.4.12+dfsg-1 (bookworm)2018
CVE-2018-11407 [CRITICAL] CVE-2018-11407: symfony - An issue was discovered in the Ldap component in Symfony 2.8.x before 2.8.37, 3....
An issue was discovered in the Ldap component in Symfony 2.8.x before 2.8.37, 3.3.x before 3.3.17, 3.4.x before 3.4.7, and 4.0.x before 4.0.7. It allows remote attackers to bypass authentication by logging in with a "null" password and valid username, which triggers an unauthenticated bind. NOTE: this issue exists because of an incomplete fix for CVE-2016-2403.
debian
CVE-2019-10913P3CRITICALCVSS 9.8fixed in symfony 3.4.22+dfsg-2 (bookworm)2019
CVE-2019-10913 [CRITICAL] CVE-2019-10913: symfony - In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1...
In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, HTTP Methods provided as verbs or using the override header may be treated as trusted input, but they are not validated, possibly causing SQL injection or XSS. This is related to symfony/http-foundation.
Scope: local
bookworm: resolved (fixed in 3.4.22+df
debian
CVE-2024-51996P3HIGHCVSS 7.5fixed in symfony 5.4.23+dfsg-1+deb12u4 (bookworm)2024
CVE-2024-51996 [HIGH] CVE-2024-51996: symfony - Symphony process is a module for the Symphony PHP framework which executes comma...
Symphony process is a module for the Symphony PHP framework which executes commands in sub-processes. When consuming a persisted remember-me cookie, Symfony does not check if the username persisted in the database matches the username attached with the cookie, leading to authentication bypass. This vulnerability is fixed in 5.4.47, 6.4.15, and 7.1.8.
Scope: local
bo
debian
CVE-2019-18888P3HIGHCVSS 7.5fixed in symfony 4.3.8+dfsg-1 (bookworm)2019
CVE-2019-18888 [HIGH] CVE-2019-18888: symfony - An issue was discovered in Symfony 2.8.0 through 2.8.50, 3.4.0 through 3.4.34, 4...
An issue was discovered in Symfony 2.8.0 through 2.8.50, 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4.3.7. If an application passes unvalidated user input as the file for which MIME type validation should occur, then arbitrary arguments are passed to the underlying file command. This is related to symfony/http-foundation (and symfony/mime in 4.3.x
debian
CVE-2020-5275P3HIGHCVSS 7.6fixed in symfony 4.4.8-1 (bookworm)2020
CVE-2020-5275 [HIGH] CVE-2020-5275: symfony - In symfony/security-http before versions 4.4.7 and 5.0.7, when a `Firewall` chec...
In symfony/security-http before versions 4.4.7 and 5.0.7, when a `Firewall` checks access control rule, it iterate overs each rule's attributes and stops as soon as the accessDecisionManager decides to grant access on the attribute, preventing the check of next attributes that should have been take into account in an unanimous strategy. The accessDecisionManager is no
debian
CVE-2018-11385P3HIGHCVSS 8.1fixed in symfony 3.4.12+dfsg-1 (bookworm)2018
CVE-2018-11385 [HIGH] CVE-2018-11385: symfony - An issue was discovered in the Security component in Symfony 2.7.x before 2.7.48...
An issue was discovered in the Security component in Symfony 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x before 4.0.11. A session fixation vulnerability within the "Guard" login feature may allow an attacker to impersonate a victim towards the web application if the session id value was previously known to the attack
debian
CVE-2019-10911P3HIGHCVSS 7.5fixed in symfony 3.4.22+dfsg-2 (bookworm)2019
CVE-2019-10911 [HIGH] CVE-2019-10911: symfony - In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1...
In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, a vulnerability would allow an attacker to authenticate as a privileged user on sites with user registration and remember me login functionality enabled. This is related to symfony/security.
Scope: local
bookworm: resolved (fixed in 3.4.22+dfsg-2)
bullseye: r
debian
CVE-2017-16654P3HIGHCVSS 7.5fixed in symfony 3.4.0+dfsg-1 (bookworm)2017
CVE-2017-16654 [HIGH] CVE-2017-16654: symfony - An issue was discovered in Symfony before 2.7.38, 2.8.31, 3.2.14, 3.3.13, 3.4-BE...
An issue was discovered in Symfony before 2.7.38, 2.8.31, 3.2.14, 3.3.13, 3.4-BETA5, and 4.0-BETA5. The Intl component includes various bundle readers that are used to read resource bundles from the local filesystem. The read() methods of these classes use a path and a locale to determine the language bundle to retrieve. The locale argument value is commonly retriev
debian
CVE-2022-24894P3MEDIUMCVSS 5.9fixed in symfony 5.4.20+dfsg-1 (bookworm)2022
CVE-2022-24894 [MEDIUM] CVE-2022-24894: symfony - Symfony is a PHP framework for web and console applications and a set of reusabl...
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. The Symfony HTTP cache system, acts as a reverse proxy: It caches entire responses (including headers) and returns them to the clients. In a recent change in the `AbstractSessionListener`, the response might contain a `Set-Cookie` header. If the Symfony HTTP cache sys
debian
CVE-2019-10912P3HIGHCVSS 7.1fixed in symfony 3.4.22+dfsg-2 (bookworm)2019
CVE-2019-10912 [HIGH] CVE-2019-10912: symfony - In Symfony before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before...
In Symfony before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, it is possible to cache objects that may contain bad user input. On serialization or unserialization, this could result in the deletion of files that the current user has access to. This is related to symfony/cache and symfony/phpunit-bridge.
Scope: local
bookworm: resolved (fixe
debian
CVE-2022-24895P3MEDIUMCVSS 6.3fixed in symfony 5.4.20+dfsg-1 (bookworm)2022
CVE-2022-24895 [MEDIUM] CVE-2022-24895: symfony - Symfony is a PHP framework for web and console applications and a set of reusabl...
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. When authenticating users Symfony by default regenerates the session ID upon login, but preserves the rest of session attributes. Because this does not clear CSRF tokens upon login, this might enables same-site attackers to bypass the CSRF protection mechanism by perf
debian
1 / 3Next →