First published: Tue Apr 16 2019(Updated: )
CVE-2019-10909: Escape validation messages in the PHP templating engine
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
composer/symfony/symfony | >=2.7.0<2.7.51>=2.8.0<2.8.50>=3.0.0<3.1.0>=3.1.0<3.2.0>=3.2.0<3.3.0>=3.3.0<3.4.0>=3.4.0<3.4.26>=4.0.0<4.1.0>=4.1.0<4.1.12>=4.2.0<4.2.7 | |
composer/drupal/core | >=7.0<7.65>=8.0.0<8.1.0>=8.1.0<8.2.0>=8.2.0<8.3.0>=8.3.0<8.4.0>=8.4.0<8.5.0>=8.5.0<8.5.14>=8.6.0<8.6.14 | |
composer/drupal/drupal | >=7.0<7.65>=8.0.0<8.1.0>=8.1.0<8.2.0>=8.2.0<8.3.0>=8.3.0<8.4.0>=8.4.0<8.5.0>=8.5.0<8.5.14>=8.6.0<8.6.14 | |
composer/symfony/framework-bundle | >=2.7.0<2.7.51>=2.8.0<2.8.50>=3.0.0<3.1.0>=3.1.0<3.2.0>=3.2.0<3.3.0>=3.3.0<3.4.0>=3.4.0<3.4.26>=4.0.0<4.1.0>=4.1.0<4.1.12>=4.2.0<4.2.7 | |
SensioLabs Symfony | >=2.7.0<2.7.51 | |
SensioLabs Symfony | >=2.8.0<2.8.50 | |
SensioLabs Symfony | >=3.4.0<3.4.26 | |
SensioLabs Symfony | >=4.1.0<4.1.12 | |
SensioLabs Symfony | >=4.2.0<4.2.7 | |
Drupal Drupal | >=8.5.0<8.5.15 | |
Drupal Drupal | >=8.6.0<8.6.15 | |
debian/symfony | 3.4.22+dfsg-2+deb10u1 3.4.22+dfsg-2+deb10u2 4.4.19+dfsg-2+deb11u3 5.4.23+dfsg-1 5.4.29+dfsg-1 5.4.30+dfsg-1 | |
composer/drupal/drupal | >=8.6.0<8.6.15 | 8.6.15 |
composer/drupal/drupal | >=8.0.0<8.5.15 | 8.5.15 |
composer/drupal/core | >=8.0.0<8.5.15 | 8.5.15 |
composer/drupal/core | >=8.6.0<8.6.15 | 8.6.15 |
composer/symfony/symfony | >=4.2.0<4.2.7 | 4.2.7 |
composer/symfony/symfony | >=4.0.0<4.1.12 | 4.1.12 |
composer/symfony/symfony | >=3.0.0<3.4.26 | 3.4.26 |
composer/symfony/symfony | >=2.8.0<2.8.50 | 2.8.50 |
composer/symfony/symfony | >=2.7.0<2.7.51 | 2.7.51 |
composer/symfony/framework-bundle | >=4.2.0<4.2.7 | 4.2.7 |
composer/symfony/framework-bundle | >=4.0.0<4.1.12 | 4.1.12 |
composer/symfony/framework-bundle | >=3.0.0<3.4.26 | 3.4.26 |
composer/symfony/framework-bundle | >=2.8.0<2.8.50 | 2.8.50 |
composer/symfony/framework-bundle | >=2.7.0<2.7.51 | 2.7.51 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2019-10909.
The severity rating of CVE-2019-10909 is 5.4 (medium).
The affected software for CVE-2019-10909 includes Symfony versions 2.7.0 to 2.7.51, 2.8.0 to 2.8.50, 3.0.0 to 3.4.26, 4.0.0 to 4.1.12, and 4.2.0 to 4.2.7.
CVE-2019-10909 is a vulnerability in Symfony where validation messages are not escaped, leading to XSS when user input is included.
Yes, you can find more information about CVE-2019-10909 at the following links: [symfony.com](https://symfony.com/cve-2019-10909), [drupal.org](https://www.drupal.org/sa-core-2019-005), [nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2019-10909).