UBUNTU-CVE-2018-11408
Dashboard / Vulnerabilities / UBUNTU-CVE-2018-11408
Summary:
Details: The security handlers in the Security component in Symfony in 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x before 4.0.11 have an Open redirect vulnerability when security.http_utils is inlined by a container. NOTE: this issue exists because of an incomplete fix for CVE-2017-16652.
References: https://ubuntu.com/security/CVE-2018-11408, https://symfony.com/blog/cve-2018-11408-open-redirect-vulnerability-on-security-handlers, https://lists.fedoraproject.org/archives/list/[email protected]/message/G4XNBMFW33H47O5TZGA7JYCVLDBCXAJV/, https://lists.fedoraproject.org/archives/list/[email protected]/message/UBQK7JDXIELADIPGZIOUCZKMAJM5LSBW/, https://lists.fedoraproject.org/archives/list/[email protected]/message/WU5N2TZFNGXDGMXMPP7LZCWTFLENF6WH/, https://www.cve.org/CVERecord?id=CVE-2018-11408
Affected packages
Package
Name: symfony
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=xenial
Affected ranges
Type: ECOSYSTEM
Events:
