CVE-2019-18889
critical · 9.8An issue was discovered in Symfony 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4.3.7. Serializing certain cache adapter interfaces could result in remote code injection. This is related to symfony/cache.
9.8
CVSS
33.2%
EPSS (exploit prob.)
98th
EPSS percentile
2019-11-21
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-94
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| sensiolabs | symfony | >= 3.4.0, <= 3.4.34 |
| sensiolabs | symfony | >= 4.2.0, <= 4.2.11 |
| sensiolabs | symfony | >= 4.3.0, <= 4.3.7 |
| fedoraproject | fedora | 31 |
Check a specific version with /api/v1/cve/match.
References
- https://github.com/symfony/symfony/releases/tag/v4.3.8
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UED22BOXTL2SSFMGYKA64ZFHGLLJG3EA/
- https://symfony.com/blog/cve-2019-18889-forbid-serializing-abstractadapter-and-tagawareadapter-instances
- https://symfony.com/blog/symfony-4-3-8-released
- https://github.com/symfony/symfony/releases/tag/v4.3.8
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UED22BOXTL2SSFMGYKA64ZFHGLLJG3EA/
- https://symfony.com/blog/cve-2019-18889-forbid-serializing-abstractadapter-and-tagawareadapter-instances
- https://symfony.com/blog/symfony-4-3-8-released
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2019-18889