#VU40585 Cross-site request forgery in Symfony - CVE-2015-8125
Published: December 7, 2015 / Updated: October 4, 2020
Symfony
SensioLabs
Description
The vulnerability allows a remote attacker to perform cross-site request forgery attacks.
The vulnerability exists due to insufficient validation of the HTTP request origin. A remote attacker can trick the victim to visit a specially crafted web page and perform arbitrary actions on behalf of the victim on the vulnerable website.
Remediation
External links
- http://lists.fedoraproject.org/pipermail/package-announce/2015-December/173271.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-December/173300.html
- http://www.debian.org/security/2015/dsa-3402
- http://www.securityfocus.com/bid/77692
- https://symfony.com/blog/cve-2015-8125-potential-remote-timing-attack-vulnerability-in-security-remember-me-service