CVE-2018-11386: Medium severity symfony vulnerability
An issue was discovered in the HttpFoundation component in Symfony 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x before 4.0.11. The PDOSessionHandler class allows storing sessions on a PDO connection. Under some configurations and with a well-crafted payload, it was possible to do a denial of service on a Symfony application without too much resources.
Other sources
CVE-2018-11386: Denial of service when using PDOSessionHandler
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-11386?
The severity of CVE-2018-11386 is medium, with a severity value of 5.9.
How does CVE-2018-11386 affect Symfony?
CVE-2018-11386 affects Symfony versions 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x before 4.0.11.
What is the vulnerability in CVE-2018-11386?
The vulnerability in CVE-2018-11386 is a denial of service vulnerability when using PDOSessionHandler in Symfony.
How can I fix CVE-2018-11386?
To fix CVE-2018-11386, update Symfony to versions 2.7.48, 2.8.41, 3.3.17, 3.4.11, or 4.0.11.
Where can I find more information about CVE-2018-11386?
You can find more information about CVE-2018-11386 at the following links: [Symfony](https://symfony.com/cve-2018-11386), [NVD](https://nvd.nist.gov/vuln/detail/CVE-2018-11386), [Fedora Project](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/G4XNBMFW33H47O5TZGA7JYCVLDBCXAJV/)