CVE-2021-41267: Webcache Poisoning in Symfony

Published Oct 9, 2021
·
Updated

CVE-2021-41267: Webcache Poisoning via X-Forwarded-Prefix and sub-request

Other sources

Description -----------

When a Symfony application is running behind a proxy or a load-balancer, you can tell Symfony to look for the X-Forwarded- HTTP headers. HTTP headers that are not part of the "trustedheaders" allowed list are ignored and protect you from "Cache poisoning" attacks.

In Symfony 5.2, we've added support for the X-Forwarded-Prefix header, but this header was accessible in sub-requests, even if it was not part of the "trustedheaders" allowed list. An attacker could leverage this opportunity to forge requests containing a X-Forwarded-Prefix HTTP header, leading to a web cache poisoning issue.

Resolution ----------

Symfony now ensures that the X-Forwarded-Prefix HTTP header is not forwarded to sub-requests when it is not trusted.

The patch for this issue is available here for branch 5.3.

Credits -------

We would like to thank Soner Sayakci for reporting the issue and Jérémy Derussé for fixing the issue.

GitHub

Symfony/Http-Kernel is the HTTP kernel component for Symfony, a PHP framework for web and console applications and a set of reusable PHP components. Headers that are not part of the "trustedheaders" allowed list are ignored and protect users from "Cache poisoning" attacks. In Symfony 5.2, maintainers added support for the X-Forwarded-Prefix headers, but this header was accessible in SubRequest, even if it was not part of the "trustedheaders" allowed list. An attacker could leverage this opportunity to forge requests containing a X-Forwarded-Prefix header, leading to a web cache poisoning issue. Versions 5.3.12 and later have a patch to ensure that the X-Forwarded-Prefix header is not forwarded to subrequests when it is not trusted.

MITRE

Affected Software

5 affected componentsFixes available
composer/symfony/http-kernel>=5.2.0, <5.3.0, >=5.3.0, <5.3.12
composer/symfony/symfony>=5.2.0, <5.3.0, >=5.3.0, <5.3.12
composer/symfony/symfony>=5.2.0<5.3.12
5.3.12
composer/symfony/http-kernel>=5.2.0<5.3.12
5.3.12
SensioLabs Symfony>=5.2.0<5.3.12

Event History

Oct 9, 2021
Advisory Published
12:10 PM
Nov 24, 2021
CVE Published
via MITRE·06:55 PM
Data Sourced
via MITRE·06:55 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is CVE-2021-41267?

CVE-2021-41267 is a vulnerability that allows web cache poisoning through the X-Forwarded-Prefix header and sub-requests.

2

What software is affected by CVE-2021-41267?

CVE-2021-41267 affects the Symfony HttpKernel library version 5.2.0 up to 5.3.12.

3

How can I fix CVE-2021-41267?

To fix CVE-2021-41267, it is recommended to upgrade the affected Symfony HttpKernel library to version 5.3.13 or higher.

4

Where can I find more information about CVE-2021-41267?

You can find more information about CVE-2021-41267 on the Symfony website at https://symfony.com/cve-2021-41267.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203