CVE-2020-15094
Description
In Symfony before versions 4.4.13 and 5.1.5, the CachingHttpClient class from the HttpClient Symfony component relies on the HttpCache class to handle requests. HttpCache uses internal headers like X-Body-Eval and X-Body-File to control the restoration of cached responses. The class was initially written with surrogate caching and ESI support in mind (all HTTP calls come from a trusted backend in that scenario). But when used by CachingHttpClient and if an attacker can control the response for a request being made by the CachingHttpClient, remote code execution is possible. This has been fixed in versions 4.4.13 and 5.1.5.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
symfony/http-kernelPackagist | >= 4.3.0, < 4.4.13 | 4.4.13 |
symfony/http-kernelPackagist | >= 5.0.0, < 5.1.5 | 5.1.5 |
symfony/symfonyPackagist | >= 4.3.0, < 4.4.13 | 4.4.13 |
symfony/symfonyPackagist | >= 5.0.0, < 5.1.5 | 5.1.5 |
Affected products
8cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*range: >=4.4.0,<4.4.13
- (no CPE)range: >= 4.4.0, < 4.4.13
cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*
- osv-coords3 versions
>= 4.4.0, < 4.4.13+ 2 more
- (no CPE)range: >= 4.4.0, < 4.4.13
- (no CPE)range: >= 4.3.0, < 4.4.13
- (no CPE)range: >= 4.3.0, < 4.4.13
Patches
Vulnerability mechanics
References
13- github.com/symfony/symfony/commit/d9910e0b33a2e0f993abff41c6fbc86951b66d78nvdPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-754h-5r27-7x3rghsaADVISORY
- github.com/symfony/symfony/security/advisories/GHSA-754h-5r27-7x3rnvdThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2020-15094ghsaADVISORY
- packagist.org/packages/symfony/http-kernelnvdProductThird Party AdvisoryWEB
- packagist.org/packages/symfony/symfonynvdProductThird Party AdvisoryWEB
- github.com/FriendsOfPHP/security-advisories/blob/master/symfony/http-kernel/CVE-2020-15094.yamlghsaWEB
- github.com/FriendsOfPHP/security-advisories/blob/master/symfony/symfony/CVE-2020-15094.yamlghsaWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/HNGUWOEETOFVH4PN3I3YO4QZHQ4AUKF3ghsaWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/VAQJXAKWPMWB7OL6QPG2ZSEQZYYPU5RCghsaWEB
- symfony.com/cve-2020-15094ghsaWEB
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HNGUWOEETOFVH4PN3I3YO4QZHQ4AUKF3/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VAQJXAKWPMWB7OL6QPG2ZSEQZYYPU5RC/nvd
News mentions
0No linked articles in our index yet.