GHSA-x92h-wmg2-6hp7
Dashboard / Vulnerabilities / GHSA-x92h-wmg2-6hp7
Summary: Invalid HTTP method overrides allow possible XSS or other attacks in Symfony
Details: In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, HTTP Methods provided as verbs or using the override header may be treated as trusted input, but they are not validated, possibly causing SQL injection or XSS. This is related to symfony/http-foundation.
References: https://nvd.nist.gov/vuln/detail/CVE-2019-10913, https://github.com/symfony/symfony/commit/944e60f083c3bffbc6a0b5112db127a10a66a8ec, https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/http-foundation/CVE-2019-10913.yaml, https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/symfony/CVE-2019-10913.yaml, https://symfony.com/blog/cve-2019-10913-reject-invalid-http-method-overrides, https://symfony.com/cve-2019-10913
Affected packages
Package
Name: symfony/http-foundation
Purl: pkg:composer/symfony/http-foundation
Affected ranges
Type: ECOSYSTEM
Events:
