CVE-2019-11325: Critical severity symfony vulnerability
An issue was discovered in Symfony before 4.2.12 and 4.3.x before 4.3.8. The VarExport component incorrectly escapes strings, allowing some specially crafted ones to escalate to execution of arbitrary PHP code. This is related to symfony/var-exporter.
Other sources
CVE-2019-11325: Fix escaping of strings in VarExporter
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2019-11325?
CVE-2019-11325 is a vulnerability related to the escaping of strings in VarExporter.
Which software is affected by CVE-2019-11325?
The vulnerability affects the Symfony framework versions 4.2.0 up to 4.2.12 and 4.3.0 up to 4.3.8, as well as the VarExporter package within Symfony.
How severe is CVE-2019-11325?
The severity of CVE-2019-11325 is not defined in the provided information.
How can I fix CVE-2019-11325?
To fix CVE-2019-11325, update the affected Symfony framework or VarExporter package to versions beyond the vulnerable range.
Where can I find more information about CVE-2019-11325?
More information about CVE-2019-11325 can be found at the following reference: [https://symfony.com/cve-2019-11325](https://symfony.com/cve-2019-11325)