CVE-2015-4050
Last modified
CVE-2015-4050 is a vulnerability of currently unknown severity. FragmentListener in the HttpKernel component in Symfony 2.3.19 through 2.3.28, 2.4.9 through 2.4.10, 2.5.4 through 2.5.11, and 2.6.0 through 2.6.7, when ESI or SSI support enabled, does not check if the _controller attribute is set, which allows remote attackers to bypass URL signing and security rules by including (1) no hash or (2) an invalid hash in a request to /_fragment.. EPSS estimates a 8.27% chance of exploitation in the next 30 days.
Description
FragmentListener in the HttpKernel component in Symfony 2.3.19 through 2.3.28, 2.4.9 through 2.4.10, 2.5.4 through 2.5.11, and 2.6.0 through 2.6.7, when ESI or SSI support enabled, does not check if the _controller attribute is set, which allows remote attackers to bypass URL signing and security rules by including (1) no hash or (2) an invalid hash in a request to /_fragment.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Sensiolabs | Symfony | 2.3.19 |
| Sensiolabs | Symfony | 2.3.20 |
| Sensiolabs | Symfony | 2.3.21 |
| Sensiolabs | Symfony | 2.3.22 |
| Sensiolabs | Symfony | 2.3.23 |
| Sensiolabs | Symfony | 2.3.24 |
| Sensiolabs | Symfony | 2.3.25 |
| Sensiolabs | Symfony | 2.3.26 |
| Sensiolabs | Symfony | 2.3.27 |
| Sensiolabs | Symfony | 2.3.28 |
| Sensiolabs | Symfony | 2.4.9 |
| Sensiolabs | Symfony | 2.4.10 |
| Sensiolabs | Symfony | 2.5.4 |
| Sensiolabs | Symfony | 2.5.5 |
| Sensiolabs | Symfony | 2.5.6 |
| Sensiolabs | Symfony | 2.5.7 |
| Sensiolabs | Symfony | 2.5.8 |
| Sensiolabs | Symfony | 2.5.9 |
| Sensiolabs | Symfony | 2.5.10 |
| Sensiolabs | Symfony | 2.5.11 |
| Sensiolabs | Symfony | 2.6.0 |
| Sensiolabs | Symfony | 2.6.1 |
| Sensiolabs | Symfony | 2.6.3 |
| Sensiolabs | Symfony | 2.6.4 |
| Sensiolabs | Symfony | 2.6.5 |
| Sensiolabs | Symfony | 2.6.6 |
| Sensiolabs | Symfony | 2.6.7 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2015-4050?
How severe is CVE-2015-4050?
How do I fix CVE-2015-4050?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2015
- CVE-2015-4042Integer overflow in the keycompare_mb function in sort.c in …9.8
- CVE-2015-4043SQL injection vulnerability in ConnX ESP HR Management 4.4.0…
- CVE-2015-4045The sudoers file in the asset discovery scanner in AlienVaul…
- CVE-2015-4046The asset discovery scanner in AlienVault OSSIM before 5.0.1…
- CVE-2015-4047racoon/gssapi.c in IPsec-Tools 0.8.2 allows remote attackers…
- CVE-2015-4049Unisys Libra 43xx, 63xx, and 83xx, and FS600 class systems w…
- CVE-2015-4051Beckhoff IPC Diagnostics before 1.8 does not properly restri…
- CVE-2015-4053The admin command in ceph-deploy before 1.5.25 uses world-re…
- CVE-2015-4054PgBouncer before 1.5.5 allows remote attackers to cause a de…
- CVE-2015-4056The System Library in VCE Vision Intelligent Operations befo…6.7
- CVE-2015-4057The "Plug-in for VMware vCenter" in VCE Vision Intelligent O…7.5
- CVE-2015-4058Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
Are you affected by CVE-2015-4050?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
