CVE-2018-11408: Medium severity symfony vulnerability
CVE-2018-11408: Open redirect vulnerability on security handlers
Other sources
The security handlers in the Security component in Symfony in 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x before 4.0.11 have an Open redirect vulnerability when security.httputils is inlined by a container. NOTE: this issue exists because of an incomplete fix for CVE-2017-16652.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-11408?
CVE-2018-11408 is an open redirect vulnerability in the security handlers of Symfony.
What is the severity of CVE-2018-11408?
The severity of CVE-2018-11408 is medium (6.1).
Which versions of Symfony are affected by CVE-2018-11408?
Symfony versions 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x before 4.0.11 are affected by CVE-2018-11408.
How can I fix CVE-2018-11408?
To fix CVE-2018-11408, you should update Symfony to version 2.7.48, 2.8.41, 3.3.17, 3.4.11, or 4.0.11.
Where can I find more information about CVE-2018-11408?
You can find more information about CVE-2018-11408 at the following references: 1. [Symfony Security Advisory](https://symfony.com/cve-2018-11408) 2. [National Vulnerability Database (NVD)](https://nvd.nist.gov/vuln/detail/CVE-2018-11408) 3. [Debian LTS Announcement](https://lists.debian.org/debian-lts-announce/2019/03/msg00009.html)