CVE-2017-16652: Medium severity symfony vulnerability
An issue was discovered in Symfony 2.7.x before 2.7.38, 2.8.x before 2.8.31, 3.2.x before 3.2.14, and 3.3.x before 3.3.13. DefaultAuthenticationSuccessHandler or DefaultAuthenticationFailureHandler takes the content of the targetpath parameter and generates a redirect response, but no check is performed on the path, which could be an absolute URL to an external domain. This Open redirect vulnerability can be exploited for example to mount effective phishing attacks.
Other sources
An issue was discovered in Symfony 2.7.x before 2.7.38, 2.8.x before 2.8.31, 3.2.x before 3.2.14, and 3.3.x before 3.3.13. DefaultAuthenticationSuccessHandler or DefaultAuthenticationFailureHandler takes the content of the targetpath parameter and generates a redirect response, but no check is performed on the path, which could be an absolute URL to an external domain. This Open redirect vulnerability can be exploited for example to mount effective phishing attacks.
CVE-2017-16652: Open redirect vulnerability on security handlers
Affected Software
Event History
Frequently Asked Questions
What is CVE-2017-16652?
CVE-2017-16652 is an open redirect vulnerability found in Symfony 2.7.x before 2.7.38, 2.8.x before 2.8.31, 3.2.x before 3.2.14, and 3.3.x before 3.3.13.
What is the severity of CVE-2017-16652?
The severity of CVE-2017-16652 is medium with a CVSS score of 6.1.
How does CVE-2017-16652 affect Symfony?
CVE-2017-16652 affects Symfony versions 2.7.x to 2.7.38, 2.8.x to 2.8.31, 3.2.x to 3.2.14, and 3.3.x to 3.3.13.
How can I fix CVE-2017-16652?
To fix CVE-2017-16652, upgrade to Symfony version 2.7.38, 2.8.31, 3.2.14, or 3.3.13.
Where can I find more information about CVE-2017-16652?
You can find more information about CVE-2017-16652 in the following references: [NVD](https://nvd.nist.gov/vuln/detail/CVE-2017-16652), [Debian LTS](https://lists.debian.org/debian-lts-announce/2019/03/msg00009.html), [Symfony Blog](https://symfony.com/blog/cve-2017-16652-open-redirect-vulnerability-on-security-handlers).