CVE-2018-19790
Summary
An open redirect was discovered in Symfony 2.7.x before 2.7.50, 2.8.x before 2.8.49, 3.x before 3.4.20, 4.0.x before 4.0.15, 4.1.x before 4.1.9 and 4.2.x before 4.2.1. By using backslashes in the `_failure_path` input field of login forms, an attacker can work around the redirection target restrictions and effectively redirect the user to any domain after login.
Impact & exploitability
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Affected products we track (1)
Recommendation
Apply the vendor fix in your normal patch cycle. Open any affected product above for its exact safe version.
Official patch: https://symfony.com/blog/cve-2018-19790-open-redirect-vulnerability-when-using-security-http ↗
Additional information
- NVD record
- https://symfony.com/blog/cve-2018-19790-open-redirect-vulnerability-when-using-security-httpPatch
- http://www.securityfocus.com/bid/106249Advisory
- https://lists.debian.org/debian-lts-announce/2019/03/msg00009.htmlAdvisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4TD3E7FZIXLVFG3SMFJPDEKPZ26TJOW7/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JZMRJ7VTHCY5AZK24G4QGX36RLUDTDKE/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OA4WVFN5FYPIXAPLWZI6N425JHHDSWAZ/
- https://seclists.org/bugtraq/2019/May/21
- https://www.debian.org/security/2019/dsa-4441