SB2012122701 - Permissions, Privileges, and Access Controls in SensioLabs Symfony
Published: December 27, 2012 Updated: August 11, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2012-6431)
The vulnerability allows a remote non-authenticated attacker to read and manipulate data.
Symfony 2.0.x before 2.0.20 does not process URL encoded data consistently within the Routing and Security components, which allows remote attackers to bypass intended URI restrictions via a doubly encoded string.
Remediation
Install update from vendor's website.