An issue was discovered in Symfony 2.8.0 through 2.8.50, 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4.3.7. The UriSigner was subject to timing attacks. This is related to symfony/http-kernel.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
History
21 Nov 2024, 04:33
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/symfony/symfony/releases/tag/v4.3.8 - Release Notes | |
References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DZNXRVHDQBNZQUCNRVZICPPBFRAUWUJX/ - | |
References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UED22BOXTL2SSFMGYKA64ZFHGLLJG3EA/ - | |
References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VXEAOEANNIVYANTMOJ42NKSU6BGNBULZ/ - | |
References | () https://symfony.com/blog/cve-2019-18887-use-constant-time-comparison-in-urisigner - Vendor Advisory | |
References | () https://symfony.com/blog/symfony-4-3-8-released - Release Notes |
07 Nov 2023, 03:07
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
Information
Published : 2019-11-21 23:15
Updated : 2024-11-21 04:33
NVD link : CVE-2019-18887
Mitre link : CVE-2019-18887
CVE.ORG link : CVE-2019-18887
JSON object : View
Products Affected
sensiolabs
- symfony
fedoraproject
- fedora
CWE
CWE-203
Observable Discrepancy