In Symfony before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, it is possible to cache objects that may contain bad user input. On serialization or unserialization, this could result in the deletion of files that the current user has access to. This is related to symfony/cache and symfony/phpunit-bridge.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2019-05-16 15:29
Updated : 2019-07-12 07:15
NVD link : CVE-2019-10912
Mitre link : CVE-2019-10912
JSON object : View
CWE
CWE-502
Deserialization of Untrusted Data
Products Affected
sensiolabs
- symfony