Code Injection in Symfony - CVE-2015-2308

 

Code Injection in Symfony - CVE-2015-2308

Published: June 24, 2015 / Updated: August 9, 2020


Vulnerability identifier: #VU40709
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2015-2308
CWE-ID: CWE-94
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

Eval injection vulnerability in the HttpCache class in HttpKernel in Symfony 2.x before 2.3.27, 2.4.x and 2.5.x before 2.5.11, and 2.6.x before 2.6.6 allows remote attackers to execute arbitrary PHP code via a language="php" attribute of a SCRIPT element.


Affected software

Symfony
Fedora
php-symfony

How to mitigate CVE-2015-2308

Install update from vendor's website.

php-symfony - addressed in versions 2.5.11-1.el7, 2.5.11-1.fc21, 2.5.11-1.fc22

External References

Related Security Bulletins