First published: Tue Apr 16 2019(Updated: )
CVE-2019-10910: Check service IDs are valid
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
composer/symfony/dependency-injection | >=2.7.0<2.7.51>=2.8.0<2.8.50>=3.0.0<3.1.0>=3.1.0<3.2.0>=3.2.0<3.3.0>=3.3.0<3.4.0>=3.4.0<3.4.26>=4.0.0<4.1.0>=4.1.0<4.1.12>=4.2.0<4.2.7 | |
composer/symfony/proxy-manager-bridge | >=2.7.0<2.7.51>=2.8.0<2.8.50>=3.0.0<3.1.0>=3.1.0<3.2.0>=3.2.0<3.3.0>=3.3.0<3.4.0>=3.4.0<3.4.26>=4.0.0<4.1.0>=4.1.0<4.1.12>=4.2.0<4.2.7 | |
composer/symfony/symfony | >=2.7.0<2.7.51>=2.8.0<2.8.50>=3.0.0<3.1.0>=3.1.0<3.2.0>=3.2.0<3.3.0>=3.3.0<3.4.0>=3.4.0<3.4.26>=4.0.0<4.1.0>=4.1.0<4.1.12>=4.2.0<4.2.7 | |
composer/symfony/symfony | >=4.2.0<4.2.7 | 4.2.7 |
composer/symfony/symfony | >=4.0.0<4.1.12 | 4.1.12 |
composer/symfony/symfony | >=3.0.0<3.4.26 | 3.4.26 |
composer/symfony/symfony | >=2.8.0<2.8.50 | 2.8.50 |
composer/symfony/symfony | >=2.7.0<2.7.51 | 2.7.51 |
composer/symfony/proxy-manager-bridge | >=4.2.0<4.2.7 | 4.2.7 |
composer/symfony/proxy-manager-bridge | >=4.0.0<4.1.12 | 4.1.12 |
composer/symfony/proxy-manager-bridge | >=3.0.0<3.4.26 | 3.4.26 |
composer/symfony/proxy-manager-bridge | >=2.8.0<2.8.50 | 2.8.50 |
composer/symfony/proxy-manager-bridge | >=2.7.0<2.7.51 | 2.7.51 |
composer/symfony/dependency-injection | >=4.2.0<4.2.7 | 4.2.7 |
composer/symfony/dependency-injection | >=4.0.0<4.1.12 | 4.1.12 |
composer/symfony/dependency-injection | >=3.0.0<3.4.26 | 3.4.26 |
composer/symfony/dependency-injection | >=2.8.0<2.8.50 | 2.8.50 |
composer/symfony/dependency-injection | >=2.7.0<2.7.51 | 2.7.51 |
SensioLabs Symfony | >=2.7.0<2.7.51 | |
SensioLabs Symfony | >=2.8.0<2.8.50 | |
SensioLabs Symfony | >=3.4.0<3.4.26 | |
SensioLabs Symfony | >=4.1.0<4.1.12 | |
SensioLabs Symfony | >=4.2.0<4.2.7 | |
Drupal Drupal | >=8.5.0<8.5.15 | |
Drupal Drupal | >=8.6.0<8.6.15 | |
debian/symfony | 3.4.22+dfsg-2+deb10u1 3.4.22+dfsg-2+deb10u2 4.4.19+dfsg-2+deb11u3 5.4.23+dfsg-1 5.4.29+dfsg-1 5.4.30+dfsg-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-10910 is a vulnerability that allows for SQL Injection and remote code execution in Symfony before versions 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7.
CVE-2019-10910 is classified as a critical vulnerability with a severity rating of 9.8 out of 10.
CVE-2019-10910 affects Symfony versions before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7.
To fix CVE-2019-10910, update your Symfony installation to version 2.7.51, 2.8.50, 3.4.26, 4.1.12, or 4.2.7, depending on the version you are using.
The Common Weakness Enumeration (CWE) of CVE-2019-10910 is CWE-89 (SQL Injection).