CVE-2017-16652
Last modified
CVE-2017-16652 is a vulnerability of currently unknown severity. An issue was discovered in Symfony 2.7.x before 2.7.38, 2.8.x before 2.8.31, 3.2.x before 3.2.14, and 3.3.x before 3.3.13. DefaultAuthenticationSuccessHandler or DefaultAuthenticationFailureHandler takes the content of the _target_path parameter and generates a redirect response, but no check is performed on the path, which could be an absolute URL to an external domain. EPSS estimates a 0.95% chance of exploitation in the next 30 days.
Description
An issue was discovered in Symfony 2.7.x before 2.7.38, 2.8.x before 2.8.31, 3.2.x before 3.2.14, and 3.3.x before 3.3.13. DefaultAuthenticationSuccessHandler or DefaultAuthenticationFailureHandler takes the content of the _target_path parameter and generates a redirect response, but no check is performed on the path, which could be an absolute URL to an external domain. This Open redirect vulnerability can be exploited for example to mount effective phishing attacks.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Sensiolabs | Symfony | > 2.7.0, < 2.7.38 |
| Sensiolabs | Symfony | > 2.8.0, < 2.8.31 |
| Sensiolabs | Symfony | > 3.2.0, < 3.2.14 |
| Sensiolabs | Symfony | >= 3.3.0, < 3.3.13 |
| Debian | Debian Linux | 8.0 |
References
- https://lists.debian.org/debian-lts-announce/2019/03/msg00009.htmlThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/03/msg00009.htmlThird Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-16652?
How severe is CVE-2017-16652?
How do I fix CVE-2017-16652?
Are you affected by CVE-2017-16652?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
