CVE-2021-41267: Webcache Poisoning in Symfony
CVE-2021-41267: Webcache Poisoning via X-Forwarded-Prefix and sub-request
Other sources
Description -----------
When a Symfony application is running behind a proxy or a load-balancer, you can tell Symfony to look for the X-Forwarded- HTTP headers. HTTP headers that are not part of the "trustedheaders" allowed list are ignored and protect you from "Cache poisoning" attacks.
In Symfony 5.2, we've added support for the X-Forwarded-Prefix header, but this header was accessible in sub-requests, even if it was not part of the "trustedheaders" allowed list. An attacker could leverage this opportunity to forge requests containing a X-Forwarded-Prefix HTTP header, leading to a web cache poisoning issue.
Resolution ----------
Symfony now ensures that the X-Forwarded-Prefix HTTP header is not forwarded to sub-requests when it is not trusted.
The patch for this issue is available here for branch 5.3.
Credits -------
We would like to thank Soner Sayakci for reporting the issue and Jérémy Derussé for fixing the issue.
— GitHub
Symfony/Http-Kernel is the HTTP kernel component for Symfony, a PHP framework for web and console applications and a set of reusable PHP components. Headers that are not part of the "trustedheaders" allowed list are ignored and protect users from "Cache poisoning" attacks. In Symfony 5.2, maintainers added support for the X-Forwarded-Prefix headers, but this header was accessible in SubRequest, even if it was not part of the "trustedheaders" allowed list. An attacker could leverage this opportunity to forge requests containing a X-Forwarded-Prefix header, leading to a web cache poisoning issue. Versions 5.3.12 and later have a patch to ensure that the X-Forwarded-Prefix header is not forwarded to subrequests when it is not trusted.
— MITRE
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-41267?
CVE-2021-41267 is a vulnerability that allows web cache poisoning through the X-Forwarded-Prefix header and sub-requests.
What software is affected by CVE-2021-41267?
CVE-2021-41267 affects the Symfony HttpKernel library version 5.2.0 up to 5.3.12.
How can I fix CVE-2021-41267?
To fix CVE-2021-41267, it is recommended to upgrade the affected Symfony HttpKernel library to version 5.3.13 or higher.
Where can I find more information about CVE-2021-41267?
You can find more information about CVE-2021-41267 on the Symfony website at https://symfony.com/cve-2021-41267.