CVE-2019-18887: High severity symfony vulnerability
An issue was discovered in Symfony 2.8.0 through 2.8.50, 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4.3.7. The UriSigner was subject to timing attacks. This is related to symfony/http-kernel.
Other sources
CVE-2019-18887: Use constant time comparison in UriSigner
When checking the signature of an URI (an ESI fragment URL for instance), the URISigner did not used a constant time string comparison function, resulting in a potential remote timing attack vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-18887?
CVE-2019-18887 is a vulnerability in Symfony 2.8.0 through 2.8.50, 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4.3.7 that allows timing attacks.
What is the severity of CVE-2019-18887?
CVE-2019-18887 has a severity rating of 8.1 (high).
How does CVE-2019-18887 affect SensioLabs Symfony?
CVE-2019-18887 affects SensioLabs Symfony versions 2.8.0 through 2.8.50, 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4.3.7.
How do I fix CVE-2019-18887?
To fix CVE-2019-18887, you should update to Symfony version 2.8.52, 3.4.35, 4.2.12, or 4.3.8.
Where can I find more information about CVE-2019-18887?
You can find more information about CVE-2019-18887 at the following references: [Symfony Advisory](https://symfony.com/cve-2019-18887), [NVD](https://nvd.nist.gov/vuln/detail/CVE-2019-18887), [GitHub Advisory](https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/http-kernel/CVE-2019-18887.yaml).