First published: Tue Apr 16 2019(Updated: )
CVE-2019-10913: Reject invalid HTTP method overrides
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
composer/symfony/symfony | >=2.7.0<2.7.51>=2.8.0<2.8.50>=3.0.0<3.1.0>=3.1.0<3.2.0>=3.2.0<3.3.0>=3.3.0<3.4.0>=3.4.0<3.4.26>=4.0.0<4.1.0>=4.1.0<4.1.12>=4.2.0<4.2.7 | |
composer/symfony/http-foundation | >=2.7.0<2.7.51>=2.8.0<2.8.50>=3.0.0<3.1.0>=3.1.0<3.2.0>=3.2.0<3.3.0>=3.3.0<3.4.0>=3.4.0<3.4.26>=4.0.0<4.1.0>=4.1.0<4.1.12>=4.2.0<4.2.7 | |
SensioLabs Symfony | >=2.7.0<2.7.51 | |
SensioLabs Symfony | >=2.8.0<2.8.50 | |
SensioLabs Symfony | >=3.4.0<3.4.26 | |
SensioLabs Symfony | >=4.1.0<4.1.12 | |
SensioLabs Symfony | >=4.2.0<4.2.7 | |
debian/symfony | 3.4.22+dfsg-2+deb10u1 3.4.22+dfsg-2+deb10u2 4.4.19+dfsg-2+deb11u3 5.4.23+dfsg-1 5.4.29+dfsg-1 5.4.30+dfsg-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-10913 is a vulnerability in Symfony that allows malicious actors to perform SQL injection or XSS attacks.
CVE-2019-10913 can be exploited by sending HTTP methods provided as verbs or using the override header that are not properly validated.
Versions before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7 of Symfony are affected by CVE-2019-10913.
To fix CVE-2019-10913, upgrade to version 2.7.51, 2.8.50, 3.4.26, 4.1.12, or 4.2.7 of Symfony.
More information about CVE-2019-10913 can be found on the Symfony website and the Debian security tracker.