Lucene search

K
nvd[email protected]NVD:CVE-2015-4050
HistoryJun 02, 2015 - 2:59 p.m.

CVE-2015-4050

2015-06-0214:59:12
CWE-284
web.nvd.nist.gov
5

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

6.5

Confidence

Low

EPSS

0.006

Percentile

78.5%

FragmentListener in the HttpKernel component in Symfony 2.3.19 through 2.3.28, 2.4.9 through 2.4.10, 2.5.4 through 2.5.11, and 2.6.0 through 2.6.7, when ESI or SSI support enabled, does not check if the _controller attribute is set, which allows remote attackers to bypass URL signing and security rules by including (1) no hash or (2) an invalid hash in a request to /_fragment.

Affected configurations

Nvd
Node
sensiolabssymfonyMatch2.3.19
OR
sensiolabssymfonyMatch2.3.20
OR
sensiolabssymfonyMatch2.3.21
OR
sensiolabssymfonyMatch2.3.22
OR
sensiolabssymfonyMatch2.3.23
OR
sensiolabssymfonyMatch2.3.24
OR
sensiolabssymfonyMatch2.3.25
OR
sensiolabssymfonyMatch2.3.26
OR
sensiolabssymfonyMatch2.3.27
OR
sensiolabssymfonyMatch2.3.28
OR
sensiolabssymfonyMatch2.4.9
OR
sensiolabssymfonyMatch2.4.10
OR
sensiolabssymfonyMatch2.5.4
OR
sensiolabssymfonyMatch2.5.5
OR
sensiolabssymfonyMatch2.5.6
OR
sensiolabssymfonyMatch2.5.7
OR
sensiolabssymfonyMatch2.5.8
OR
sensiolabssymfonyMatch2.5.9
OR
sensiolabssymfonyMatch2.5.10
OR
sensiolabssymfonyMatch2.5.11
OR
sensiolabssymfonyMatch2.6.0
OR
sensiolabssymfonyMatch2.6.1
OR
sensiolabssymfonyMatch2.6.3
OR
sensiolabssymfonyMatch2.6.4
OR
sensiolabssymfonyMatch2.6.5
OR
sensiolabssymfonyMatch2.6.6
OR
sensiolabssymfonyMatch2.6.7
VendorProductVersionCPE
sensiolabssymfony2.3.19cpe:2.3:a:sensiolabs:symfony:2.3.19:*:*:*:*:*:*:*
sensiolabssymfony2.3.20cpe:2.3:a:sensiolabs:symfony:2.3.20:*:*:*:*:*:*:*
sensiolabssymfony2.3.21cpe:2.3:a:sensiolabs:symfony:2.3.21:*:*:*:*:*:*:*
sensiolabssymfony2.3.22cpe:2.3:a:sensiolabs:symfony:2.3.22:*:*:*:*:*:*:*
sensiolabssymfony2.3.23cpe:2.3:a:sensiolabs:symfony:2.3.23:*:*:*:*:*:*:*
sensiolabssymfony2.3.24cpe:2.3:a:sensiolabs:symfony:2.3.24:*:*:*:*:*:*:*
sensiolabssymfony2.3.25cpe:2.3:a:sensiolabs:symfony:2.3.25:*:*:*:*:*:*:*
sensiolabssymfony2.3.26cpe:2.3:a:sensiolabs:symfony:2.3.26:*:*:*:*:*:*:*
sensiolabssymfony2.3.27cpe:2.3:a:sensiolabs:symfony:2.3.27:*:*:*:*:*:*:*
sensiolabssymfony2.3.28cpe:2.3:a:sensiolabs:symfony:2.3.28:*:*:*:*:*:*:*
Rows per page:
1-10 of 271

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

6.5

Confidence

Low

EPSS

0.006

Percentile

78.5%