CVE-2018-19790: Medium severity symfony vulnerability
An open redirect was discovered in Symfony 2.7.x before 2.7.50, 2.8.x before 2.8.49, 3.x before 3.4.20, 4.0.x before 4.0.15, 4.1.x before 4.1.9 and 4.2.x before 4.2.1. By using backslashes in the failurepath input field of login forms, an attacker can work around the redirection target restrictions and effectively redirect the user to any domain after login.
Other sources
CVE-2018-19790: Open Redirect Vulnerability on login
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2018-19790?
CVE-2018-19790 is an open redirect vulnerability in Symfony.
How severe is CVE-2018-19790?
CVE-2018-19790 has a severity rating of 6.1 (medium).
Which versions of Symfony are affected by CVE-2018-19790?
Symfony versions 2.7.x before 2.7.50, 2.8.x before 2.8.49, 3.x before 3.4.20, 4.0.x before 4.0.15, 4.1.x before 4.1.9, and 4.2.x before 4.2.1 are affected by CVE-2018-19790.
How can an attacker exploit CVE-2018-19790?
An attacker can exploit CVE-2018-19790 by using backslashes in the _failure_path input field of login forms to bypass the redirection target restrictions.
Where can I find more information about CVE-2018-19790?
You can find more information about CVE-2018-19790 at the following links: [Symfony Advisory](https://symfony.com/cve-2018-19790), [Symfony Blog](https://symfony.com/blog/cve-2018-19790-open-redirect-vulnerability-when-using-security-http), [Debian Security Tracker](https://security-tracker.debian.org/tracker/CVE-2018-19790)