Critical severityNVD Advisory· Published Nov 21, 2019· Updated Aug 4, 2024
CVE-2019-11325
CVE-2019-11325
Description
An issue was discovered in Symfony before 4.2.12 and 4.3.x before 4.3.8. The VarExport component incorrectly escapes strings, allowing some specially crafted ones to escalate to execution of arbitrary PHP code. This is related to symfony/var-exporter.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
symfony/symfonyPackagist | >= 4.2.0, < 4.2.12 | 4.2.12 |
symfony/symfonyPackagist | >= 4.3.0, < 4.3.8 | 4.3.8 |
symfony/var-exporterPackagist | >= 4.2.0, < 4.2.12 | 4.2.12 |
symfony/var-exporterPackagist | >= 4.3.0, < 4.3.8 | 4.3.8 |
Affected products
3- Symfony/Symfonydescription
- ghsa-coords2 versions
>= 4.2.0, < 4.2.12+ 1 more
- (no CPE)range: >= 4.2.0, < 4.2.12
- (no CPE)range: >= 4.2.0, < 4.2.12
Patches
Vulnerability mechanics
References
9- github.com/advisories/GHSA-w4rc-rx25-8m86ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2019-11325ghsaADVISORY
- github.com/FriendsOfPHP/security-advisories/blob/master/symfony/symfony/CVE-2019-11325.yamlghsaWEB
- github.com/FriendsOfPHP/security-advisories/blob/master/symfony/var-exporter/CVE-2019-11325.yamlghsaWEB
- github.com/symfony/symfony/releases/tag/v4.3.8ghsax_refsource_CONFIRMWEB
- github.com/symfony/var-exporter/compare/d8bf442...57e00f3ghsax_refsource_MISCWEB
- symfony.com/blog/cve-2019-11325-fix-escaping-of-strings-in-varexporterghsax_refsource_CONFIRMWEB
- symfony.com/blog/symfony-4-3-8-releasedghsax_refsource_CONFIRMWEB
- symfony.com/cve-2019-11325ghsaWEB
News mentions
0No linked articles in our index yet.