CVE-2019-10912
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
In Symfony before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, it is possible to cache objects that may contain bad user input. On serialization or unserialization, this could result in the deletion of files that the current user has access to. This is related to symfony/cache and symfony/phpunit-bridge.
En Symfony versión anterior a 2.8.50, versión 3.x anterior a 3.4.26, versión 4.x anterior a 4.1.12 y versión 4.2.x anterior a 4.2.7, es posible guardar en caché objetos que pueden contener información errada del usuario. En la serialización o unserialization, esto podría resultar en la eliminación de archivos a los que el usuario actual tiene acceso. Esto está relacionado con Symfony/cache y Symfony/ phpunit-bridge.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-04-07 CVE Reserved
- 2019-05-10 CVE Published
- 2024-08-04 CVE Updated
- 2024-10-06 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-502: Deserialization of Untrusted Data
CAPEC
References (13)
URL | Tag | Source |
---|---|---|
https://seclists.org/bugtraq/2019/May/21 | Mailing List | |
https://symfony.com/blog/cve-2019-10912-prevent-destructors-with-side-effects-from-being-unserialized | Third Party Advisory | |
https://typo3.org/security/advisory/typo3-core-sa-2019-016 | X_refsource_confirm |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://github.com/symfony/symfony/commit/4fb975281634b8d49ebf013af9e502e67c28816b | 2023-11-07 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Sensiolabs Search vendor "Sensiolabs" | Symfony Search vendor "Sensiolabs" for product "Symfony" | >= 2.8.0 < 2.8.50 Search vendor "Sensiolabs" for product "Symfony" and version " >= 2.8.0 < 2.8.50" | - |
Affected
| ||||||
Sensiolabs Search vendor "Sensiolabs" | Symfony Search vendor "Sensiolabs" for product "Symfony" | >= 3.4.0 < 3.4.26 Search vendor "Sensiolabs" for product "Symfony" and version " >= 3.4.0 < 3.4.26" | - |
Affected
| ||||||
Sensiolabs Search vendor "Sensiolabs" | Symfony Search vendor "Sensiolabs" for product "Symfony" | >= 4.1.0 < 4.1.12 Search vendor "Sensiolabs" for product "Symfony" and version " >= 4.1.0 < 4.1.12" | - |
Affected
| ||||||
Sensiolabs Search vendor "Sensiolabs" | Symfony Search vendor "Sensiolabs" for product "Symfony" | >= 4.2.0 < 4.2.7 Search vendor "Sensiolabs" for product "Symfony" and version " >= 4.2.0 < 4.2.7" | - |
Affected
|