Input validation error in Symfony - CVE-2015-8124

 

Input validation error in Symfony - CVE-2015-8124

Published: December 7, 2015 / Updated: August 9, 2020


Vulnerability identifier: #VU40586
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2015-8124
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

Session fixation vulnerability in the "Remember Me" login feature in Symfony 2.3.x before 2.3.35, 2.6.x before 2.6.12, and 2.7.x before 2.7.7 allows remote attackers to hijack web sessions via a session id. <a href="https://cwe.mitre.org/data/definitions/384.htm">CWE-384: Session Fixation</a>


Affected software

Symfony
Fedora
php-twig
php-symfony

How to mitigate CVE-2015-8124

Install update from vendor's website.

php-twig - addressed in versions 1.23.1-2.el7, 1.23.1-2.fc22, 1.23.1-2.fc23
php-symfony - addressed in versions 2.7.7-2.el7, 2.7.7-2.fc22, 2.7.7-2.fc23

External References

Related Security Bulletins