An issue was discovered in Symfony before 4.2.12 and 4.3.x before 4.3.8. The VarExport component incorrectly escapes strings, allowing some specially crafted ones to escalate to execution of arbitrary PHP code. This is related to symfony/var-exporter.
github.com/FriendsOfPHP/security-advisories/blob/master/symfony/symfony/CVE-2019-11325.yaml
github.com/FriendsOfPHP/security-advisories/blob/master/symfony/var-exporter/CVE-2019-11325.yaml
github.com/symfony/symfony/releases/tag/v4.3.8
github.com/symfony/var-exporter/compare/d8bf442...57e00f3
nvd.nist.gov/vuln/detail/CVE-2019-11325
symfony.com/blog/cve-2019-11325-fix-escaping-of-strings-in-varexporter
symfony.com/blog/symfony-4-3-8-released
symfony.com/cve-2019-11325