Incorrect Comparison in Symfony - CVE-2019-18887
Published: November 19, 2019 / Updated: November 19, 2019
Vulnerability details
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists within the HttpKernel component in Symfony when checking the signature of an URI (an ESI fragment URL for
instance) due to the URISigner does not use a constant time string comparison
function. A remote attacker can perform a timing attack and gain access to sensitive functionality.
Affected software
symfony (Debian package)
php-symfony
php-symfony3
Fedora
How to mitigate CVE-2019-18887
symfony (Debian package) - addressed in versions 2.8.7+dfsg-1.3+deb9u3, 3.4.22+dfsg-2+deb10u1
php-symfony - addressed in versions 2.8.52-1.fc30, 2.8.52-1.fc31
php-symfony3 - update to 3.4.35-2.fc31