First published: Fri Jul 20 2018(Updated: )
** DISPUTED ** The debug handler in Symfony before v2.7.33, 2.8.x before v2.8.26, 3.x before v3.2.13, and 3.3.x before v3.3.6 has XSS via an array key during exception pretty printing in ExceptionHandler.php, as demonstrated by a /_debugbar/open?op=get URI. NOTE: the vendor's position is that this is not a vulnerability because the debug tools are not intended for production use. NOTE: the Symfony Debug component is used by Laravel Debugbar.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SensioLabs Symfony | <2.7.33 | |
SensioLabs Symfony | >=2.8.0<2.8.26 | |
SensioLabs Symfony | >=3.0.0<3.2.13 | |
SensioLabs Symfony | >=3.3.0<3.3.6 | |
<2.7.33 | ||
>=2.8.0<2.8.26 | ||
>=3.0.0<3.2.13 | ||
>=3.3.0<3.3.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this issue is CVE-2017-18343.
The severity level of CVE-2017-18343 is medium.
SensioLabs Symfony versions 2.7.33, 2.8.x (from 2.8.0 to 2.8.26), 3.x (from 3.0.0 to 3.2.13), and 3.3.x (from 3.3.0 to 3.3.6) are affected by CVE-2017-18343.
The Common Weakness Enumeration (CWE) ID associated with CVE-2017-18343 is CWE-79.
To fix the vulnerability, it is recommended to update SensioLabs Symfony to the patched versions as mentioned in the references.