First published: Fri May 25 2018(Updated: )
CVE-2018-11408: Open redirect vulnerability on security handlers
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
composer/symfony/symfony | >=2.7.38<2.7.48>=2.8.0<2.8.41>=3.0.0<3.1.0>=3.1.0<3.2.0>=3.2.0<3.3.0>=3.3.0<3.3.17>=3.4.0<3.4.11>=4.0.0<4.0.11 | |
composer/symfony/security-bundle | >=2.7.38<2.7.48>=2.8.0<2.8.41>=3.0.0<3.1.0>=3.1.0<3.2.0>=3.2.0<3.3.0>=3.3.0<3.3.17>=3.4.0<3.4.11>=4.0.0<4.0.11 | |
composer/symfony/symfony | >=4.0.0<4.0.11 | 4.0.11 |
composer/symfony/symfony | >=3.4.0<3.4.11 | 3.4.11 |
composer/symfony/symfony | >=3.3.0<3.3.17 | 3.3.17 |
composer/symfony/symfony | >=2.8.0<2.8.41 | 2.8.41 |
composer/symfony/symfony | >=2.7.0<2.7.48 | 2.7.48 |
SensioLabs Symfony | >=2.7.0<2.7.48 | |
SensioLabs Symfony | >=2.8.0<2.8.41 | |
SensioLabs Symfony | >=3.3.0<3.3.17 | |
SensioLabs Symfony | >=3.4.0<3.4.11 | |
SensioLabs Symfony | >=4.0.0<4.0.11 | |
Debian Debian Linux | =8.0 | |
composer/symfony/security-bundle | >=4.0.0<4.0.11 | 4.0.11 |
composer/symfony/security-bundle | >=3.4.0<3.4.11 | 3.4.11 |
composer/symfony/security-bundle | >=3.3.0<3.3.17 | 3.3.17 |
composer/symfony/security-bundle | >=2.8.0<2.8.41 | 2.8.41 |
composer/symfony/security-bundle | >=2.7.0<2.7.48 | 2.7.48 |
>=2.7.0<2.7.48 | ||
>=2.8.0<2.8.41 | ||
>=3.3.0<3.3.17 | ||
>=3.4.0<3.4.11 | ||
>=4.0.0<4.0.11 | ||
=8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-11408 is an open redirect vulnerability in the security handlers of Symfony.
The severity of CVE-2018-11408 is medium (6.1).
Symfony versions 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x before 4.0.11 are affected by CVE-2018-11408.
To fix CVE-2018-11408, you should update Symfony to version 2.7.48, 2.8.41, 3.3.17, 3.4.11, or 4.0.11.
You can find more information about CVE-2018-11408 at the following references: 1. [Symfony Security Advisory](https://symfony.com/cve-2018-11408) 2. [National Vulnerability Database (NVD)](https://nvd.nist.gov/vuln/detail/CVE-2018-11408) 3. [Debian LTS Announcement](https://lists.debian.org/debian-lts-announce/2019/03/msg00009.html)