CVE-2012-6432: Medium severity SensioLabs Symfony vulnerability
Code execution vulnerability via the "internal" routes
Other sources
Symfony 2.0.x before 2.0.20, 2.1.x before 2.1.5, and 2.2-dev, when the internal routes configuration is enabled, allows remote attackers to access arbitrary services via vectors involving a URI beginning with a /internal substring.
Symfony 2.0.x before 2.0.20, 2.1.x before 2.1.5, and 2.2-dev, when the internal routes configuration is enabled, allows remote attackers to access arbitrary services via vectors involving a URI beginning with a /internal substring.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-6432?
CVE-2012-6432 is considered a critical vulnerability due to the potential for remote code execution.
How do I fix CVE-2012-6432?
To fix CVE-2012-6432, you should upgrade to Symfony version 2.0.20 or 2.1.5 or later.
What software is affected by CVE-2012-6432?
CVE-2012-6432 affects Symfony versions 2.0.x before 2.0.20, 2.1.x before 2.1.5, and 2.2-dev.
What happens if CVE-2012-6432 is exploited?
If CVE-2012-6432 is exploited, attackers could gain access to arbitrary services through internal routes.
Is there a workaround for CVE-2012-6432?
While upgrading is the best solution, temporarily disabling internal routes may help mitigate the risk of CVE-2012-6432.