First published: Wed Nov 13 2019(Updated: )
An issue was discovered in Symfony 2.8.0 through 2.8.50, 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4.3.7. The UriSigner was subject to timing attacks. This is related to symfony/http-kernel.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
composer/symfony/symfony | >=2.2.0<2.3.0>=2.3.0<2.4.0>=2.4.0<2.5.0>=2.5.0<2.6.0>=2.6.0<2.7.0>=2.7.0<2.8.0>=2.8.0<2.8.52>=3.0.0<3.1.0>=3.1.0<3.2.0>=3.2.0<3.3.0>=3.3.0<3.4.0>=3.4.0<3.4.35>=4.0.0<4.1.0>=4.1.0<4.2.0>=4.2.0<4.2.12>=4.3.0<4.3.8 | |
composer/symfony/http-kernel | >=2.2.0<2.3.0>=2.3.0<2.4.0>=2.4.0<2.5.0>=2.5.0<2.6.0>=2.6.0<2.7.0>=2.7.0<2.8.0>=2.8.0<2.8.52>=3.0.0<3.1.0>=3.1.0<3.2.0>=3.2.0<3.3.0>=3.3.0<3.4.0>=3.4.0<3.4.35>=4.0.0<4.1.0>=4.1.0<4.2.0>=4.2.0<4.2.12>=4.3.0<4.3.8 | |
composer/symfony/symfony | >=4.3.0<4.3.8 | 4.3.8 |
composer/symfony/symfony | >=4.0.0<4.2.12 | 4.2.12 |
composer/symfony/symfony | >=3.0.0<3.4.35 | 3.4.35 |
composer/symfony/symfony | >=2.2.0<2.8.52 | 2.8.52 |
composer/symfony/http-kernel | >=4.3.0<4.3.8 | 4.3.8 |
composer/symfony/http-kernel | >=4.0.0<4.2.12 | 4.2.12 |
composer/symfony/http-kernel | >=3.0.0<3.4.35 | 3.4.35 |
composer/symfony/http-kernel | >=2.2.0<2.8.52 | 2.8.52 |
SensioLabs Symfony | >=2.8.0<=2.8.50 | |
SensioLabs Symfony | >=3.4.0<=3.4.34 | |
SensioLabs Symfony | >=4.2.0<=4.2.11 | |
SensioLabs Symfony | >=4.3.0<=4.3.7 | |
Fedoraproject Fedora | =30 | |
Fedoraproject Fedora | =31 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-18887 is a vulnerability in Symfony 2.8.0 through 2.8.50, 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4.3.7 that allows timing attacks.
CVE-2019-18887 has a severity rating of 8.1 (high).
CVE-2019-18887 affects SensioLabs Symfony versions 2.8.0 through 2.8.50, 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4.3.7.
To fix CVE-2019-18887, you should update to Symfony version 2.8.52, 3.4.35, 4.2.12, or 4.3.8.
You can find more information about CVE-2019-18887 at the following references: [Symfony Advisory](https://symfony.com/cve-2019-18887), [NVD](https://nvd.nist.gov/vuln/detail/CVE-2019-18887), [GitHub Advisory](https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/http-kernel/CVE-2019-18887.yaml).