CVE-2012-6431
UnknownEPSS 1.88%
Last modified
CVE-2012-6431 is a vulnerability of currently unknown severity. Symfony 2.0.x before 2.0.20 does not process URL encoded data consistently within the Routing and Security components, which allows remote attackers to bypass intended URI restrictions via a doubly encoded string.. EPSS estimates a 1.88% chance of exploitation in the next 30 days.
Description
Symfony 2.0.x before 2.0.20 does not process URL encoded data consistently within the Routing and Security components, which allows remote attackers to bypass intended URI restrictions via a doubly encoded string.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Sensiolabs | Symfony | 2.0.0 |
| Sensiolabs | Symfony | 2.0.1 |
| Sensiolabs | Symfony | 2.0.2 |
| Sensiolabs | Symfony | 2.0.3 |
| Sensiolabs | Symfony | 2.0.4 |
| Sensiolabs | Symfony | 2.0.5 |
| Sensiolabs | Symfony | 2.0.6 |
| Sensiolabs | Symfony | 2.0.7 |
| Sensiolabs | Symfony | 2.0.8 |
| Sensiolabs | Symfony | 2.0.9 |
| Sensiolabs | Symfony | 2.0.10 |
| Sensiolabs | Symfony | 2.0.11 |
| Sensiolabs | Symfony | 2.0.12 |
| Sensiolabs | Symfony | 2.0.13 |
| Sensiolabs | Symfony | 2.0.14 |
| Sensiolabs | Symfony | 2.0.15 |
| Sensiolabs | Symfony | 2.0.16 |
| Sensiolabs | Symfony | 2.0.17 |
| Sensiolabs | Symfony | 2.0.18 |
| Sensiolabs | Symfony | 2.0.19 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2012-6431?
Symfony 2.0.x before 2.0.20 does not process URL encoded data consistently within the Routing and Security components, which allows remote attackers to bypass intended URI restrictions via a doubly encoded string.
How severe is CVE-2012-6431?
Severity scoring for CVE-2012-6431 is pending analysis. The EPSS model estimates a 1.88% probability of exploitation in the next 30 days.
How do I fix CVE-2012-6431?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2012
- CVE-2012-6422The kernel in Samsung Galaxy S2, Galaxy Note 2, MEIZU MX, an…
- CVE-2012-6426LemonLDAP::NG before 1.2.3 does not use the signature-verifi…
- CVE-2012-6427The Carlo Gavazzi EOS-Box does not check the validity of t…
- CVE-2012-6428The Carlo Gavazzi EOS-Box stores hard-coded passwords in t…
- CVE-2012-6429Buffer overflow in the PrepareSync method in the SyncService…
- CVE-2012-6430Cross-site scripting (XSS) vulnerability in Open Solution Qu…
- CVE-2012-6432Symfony 2.0.x before 2.0.20, 2.1.x before 2.1.5, and 2.2-dev…
- CVE-2012-6433Cross-site request forgery (CSRF) vulnerability in e107_admi…
- CVE-2012-6434Multiple cross-site request forgery (CSRF) vulnerabilities i…
- CVE-2012-6435When an affected product receives a valid CIP message from a…7.5
- CVE-2012-6436The device does not properly validate the data being sent to…7.5
- CVE-2012-6437The device does not properly authenticate users and the pote…9.8
Are you affected by CVE-2012-6431?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
