Vulnerability Description
In Symfony before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, it is possible to cache objects that may contain bad user input. On serialization or unserialization, this could result in the deletion of files that the current user has access to. This is related to symfony/cache and symfony/phpunit-bridge.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sensiolabs | Symfony | >= 2.8.0, < 2.8.50 |
Related Weaknesses (CWE)
References
- https://github.com/symfony/symfony/commit/4fb975281634b8d49ebf013af9e502e67c2881PatchThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://seclists.org/bugtraq/2019/May/21
- https://symfony.com/blog/cve-2019-10912-prevent-destructors-with-side-effects-frThird Party Advisory
- https://typo3.org/security/advisory/typo3-core-sa-2019-016/
- https://www.debian.org/security/2019/dsa-4441
- https://github.com/symfony/symfony/commit/4fb975281634b8d49ebf013af9e502e67c2881PatchThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
FAQ
What is CVE-2019-10912?
CVE-2019-10912 is a vulnerability with a CVSS score of 7.1 (HIGH). In Symfony before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, it is possible to cache objects that may contain bad user input. On serialization or unserialization, this could...
How severe is CVE-2019-10912?
CVE-2019-10912 has been rated HIGH with a CVSS base score of 7.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-10912?
Check the references section above for vendor advisories and patch information. Affected products include: Sensiolabs Symfony.