CVE-2020-5274: Exceptions displayed in non-debug configurations in Symfony

Published Mar 30, 2020
·
Updated

CVE-2020-5274: Fix Exception message escaping rendered by ErrorHandler

Other sources

Description -----------

When ErrorHandler renders an exception HTML page, it uses un-escaped properties from the related Exception class to render the stacktrace. The security issue comes from the fact that the stacktraces were also displayed in non-debug environments.

Resolution ----------

The ErrorHandler class now escapes all properties coming from the related Exception, and the stacktrace is not displayed anymore in non-debug environments.

The patches for this issue are available here and here for branch 4.4.

Credits -------

I would like to thank Luka Sikic for reporting & Yonel Ceruto and Jérémy Derussé for fixing the issue.

GitHub

In Symfony before versions 5.0.5 and 4.4.5, some properties of the Exception were not properly escaped when the ErrorHandler rendered it stacktrace. In addition, the stacktrace were displayed even in a non-debug configuration. The ErrorHandler now escape alls properties of the exception, and the stacktrace is only display in debug configuration. This issue is patched in symfony/http-foundation versions 4.4.5 and 5.0.5

Affected Software

8 affected componentsFixes available
composer/symfony/symfony>=4.4.0, <4.4.4, >=5.0.0, <5.0.4
composer/symfony/error-handler>=4.4.0, <4.4.4, >=5.0.0, <5.0.4
composer/symfony/symfony>=5.0.0<5.0.4
5.0.4
composer/symfony/symfony>=4.4.0<4.4.4
4.4.4
composer/symfony/error-handler>=5.0.0<5.0.4
5.0.4
composer/symfony/error-handler>=4.4.0<4.4.4
4.4.4
SensioLabs Symfony>=4.4.0<4.4.4
SensioLabs Symfony>=5.0.0<5.0.4

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade composer/symfony/symfony to a version that resolves this vulnerability.

    Fixed in 5.0.4
  2. Upgrade

    Upgrade composer/symfony/symfony to a version that resolves this vulnerability.

    Fixed in 4.4.4
  3. Upgrade

    Upgrade composer/symfony/error-handler to a version that resolves this vulnerability.

    Fixed in 5.0.4
  4. Upgrade

    Upgrade composer/symfony/error-handler to a version that resolves this vulnerability.

    Fixed in 4.4.4
  5. Upgrade

    Upgrade symfony/http-foundation to a version that resolves this vulnerability.

    Fixed in 4.4.5
  6. Upgrade

    Upgrade symfony/http-foundation to a version that resolves this vulnerability.

    Fixed in 5.0.5

Event History

Mar 30, 2020
Advisory Published
02:00 PM
CVE Published
via MITRE·07:40 PM
Data Sourced
via MITRE·07:40 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 PM
RemedyDescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is CVE-2020-5274?

CVE-2020-5274 is a vulnerability in Symfony before versions 5.0.5 and 4.4.5.

2

What is the severity of CVE-2020-5274?

The severity of CVE-2020-5274 is medium with a CVSS score of 5.4.

3

How does CVE-2020-5274 affect Symfony and ErrorHandler?

CVE-2020-5274 affects Symfony versions 4.4.0 to 4.4.4 and 5.0.0 to 5.0.4, as well as ErrorHandler versions in the same range.

4

What is the fix for CVE-2020-5274?

To fix CVE-2020-5274, upgrade to Symfony version 4.4.5 or 5.0.5, and upgrade ErrorHandler accordingly.

5

Are there any references for CVE-2020-5274?

Yes, you can find more information about CVE-2020-5274 at the following references: [link1], [link2], [link3].

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203