Open redirect in Symfony - CVE-2018-11408

 

Open redirect in Symfony - CVE-2018-11408

Published: June 13, 2018 / Updated: July 17, 2020


Vulnerability identifier: #VU31285
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-11408
CWE-ID: CWE-601
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

The security handlers in the Security component in Symfony in 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x before 4.0.11 have an Open redirect vulnerability when security.http_utils is inlined by a container. NOTE: this issue exists because of an incomplete fix for CVE-2017-16652.


Affected software

Symfony
Fedora
php-symfony
php-symfony3
php-symfony4

How to mitigate CVE-2018-11408

Install update from vendor's website.

Symfony - update to 4.0.11
php-symfony - addressed in versions 2.8.41-1.fc28, 2.8.42-1.fc27
php-symfony3 - addressed in versions 3.3.17-1.fc27, 3.4.11-1.fc28
php-symfony4 - update to 4.0.11-1.fc28

External References

Related Security Bulletins