First published: Wed Nov 13 2019(Updated: )
An issue was discovered in Symfony 2.8.0 through 2.8.50, 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4.3.7. If an application passes unvalidated user input as the file for which MIME type validation should occur, then arbitrary arguments are passed to the underlying file command. This is related to symfony/http-foundation (and symfony/mime in 4.3.x).
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
composer/symfony/symfony | >=2.0.0<2.1.0>=2.1.0<2.2.0>=2.2.0<2.3.0>=2.3.0<2.4.0>=2.4.0<2.5.0>=2.5.0<2.6.0>=2.6.0<2.7.0>=2.7.0<2.8.0>=2.8.0<2.8.52>=3.0.0<3.1.0>=3.1.0<3.2.0>=3.2.0<3.3.0>=3.3.0<3.4.0>=3.4.0<3.4.35>=4.0.0<4.1.0>=4.1.0<4.2.0>=4.2.0<4.2.12>=4.3.0<4.3.8 | |
composer/symfony/mime | >=4.3.0<4.3.8 | |
composer/symfony/http-foundation | >=2.0.0<2.1.0>=2.1.0<2.2.0>=2.2.0<2.3.0>=2.3.0<2.4.0>=2.4.0<2.5.0>=2.5.0<2.6.0>=2.6.0<2.7.0>=2.7.0<2.8.0>=2.8.0<2.8.52>=3.0.0<3.1.0>=3.1.0<3.2.0>=3.2.0<3.3.0>=3.3.0<3.4.0>=3.4.0<3.4.35>=4.0.0<4.1.0>=4.1.0<4.2.0>=4.2.0<4.2.12>=4.3.0<4.3.8 | |
SensioLabs Symfony | >=2.8.0<=2.8.50 | |
SensioLabs Symfony | >=3.4.0<=3.4.34 | |
SensioLabs Symfony | >=4.2.0<=4.2.11 | |
SensioLabs Symfony | >=4.3.0<=4.3.7 | |
Fedoraproject Fedora | =30 | |
Fedoraproject Fedora | =31 | |
composer/symfony/symfony | >=4.3.0<4.3.8 | 4.3.8 |
composer/symfony/symfony | >=4.0.0<4.2.12 | 4.2.12 |
composer/symfony/symfony | >=3.0.0<3.4.35 | 3.4.35 |
composer/symfony/symfony | >=2.0.0<2.8.52 | 2.8.52 |
composer/symfony/mime | >=4.3.0<4.3.8 | 4.3.8 |
composer/symfony/http-foundation | >=4.3.0<4.3.8 | 4.3.8 |
composer/symfony/http-foundation | >=4.0.0<4.2.12 | 4.2.12 |
composer/symfony/http-foundation | >=3.0.0<3.4.35 | 3.4.35 |
composer/symfony/http-foundation | >=2.0.0<2.8.52 | 2.8.52 |
>=2.8.0<=2.8.50 | ||
>=3.4.0<=3.4.34 | ||
>=4.2.0<=4.2.11 | ||
>=4.3.0<=4.3.7 | ||
=30 | ||
=31 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-18888 is a vulnerability that allows argument injection in a MimeTypeGuesser.
The affected software includes Symfony HttpFoundation, Symfony Mime, and Symfony itself.
To fix CVE-2019-18888, update the affected Symfony packages to versions 2.8.53, 3.4.36, 4.2.13, or 4.3.9 or higher.
The severity of CVE-2019-18888 is medium.
More information about CVE-2019-18888 can be found at the following link: https://symfony.com/cve-2019-18888