CVE-2017-18343: XSS
DISPUTED The debug handler in Symfony before v2.7.33, 2.8.x before v2.8.26, 3.x before v3.2.13, and 3.3.x before v3.3.6 has XSS via an array key during exception pretty printing in ExceptionHandler.php, as demonstrated by a /debugbar/open?op=get URI. NOTE: the vendor's position is that this is not a vulnerability because the debug tools are not intended for production use. NOTE: the Symfony Debug component is used by Laravel Debugbar.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2017-18343.
What is the severity level of CVE-2017-18343?
The severity level of CVE-2017-18343 is medium.
What software is affected by CVE-2017-18343?
SensioLabs Symfony versions 2.7.33, 2.8.x (from 2.8.0 to 2.8.26), 3.x (from 3.0.0 to 3.2.13), and 3.3.x (from 3.3.0 to 3.3.6) are affected by CVE-2017-18343.
What is the Common Weakness Enumeration (CWE) ID associated with CVE-2017-18343?
The Common Weakness Enumeration (CWE) ID associated with CVE-2017-18343 is CWE-79.
How can I fix the vulnerability in SensioLabs Symfony?
To fix the vulnerability, it is recommended to update SensioLabs Symfony to the patched versions as mentioned in the references.