Record summary

CVE-2015-4050 has a selected CVSS score of 4.3; EIP currently links 1 Nuclei template.

Description

FragmentListener in the HttpKernel component in Symfony 2.3.19 through 2.3.28, 2.4.9 through 2.4.10, 2.5.4 through 2.5.11, and 2.6.0 through 2.6.7, when ESI or SSI support enabled, does not check if the _controller attribute is set, which allows remote attackers to bypass URL signing and security rules by including (1) no hash or (2) an invalid hash in a request to /_fragment.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Affected products and versions

2
ProductSourceVersion rangeStatus
GitHub Advisory2.3.19 to < 2.3.29 · Fixed in 2.3.29affected
2.5.4 to < 2.5.12 · Fixed in 2.5.12affected
2.6.0 to < 2.6.8 · Fixed in 2.6.8affected
2.4.9 to ≤ 2.4.10affected
GitHub Advisory2.3.19 to < 2.3.29 · Fixed in 2.3.29affected
2.4.9 to ≤ 2.4.10affected
2.5.4 to < 2.5.12 · Fixed in 2.5.12affected
2.6.0 to < 2.6.8 · Fixed in 2.6.8affected

Nuclei templates

1
ProjectDiscoveryMEDIUMSymfony - Authentication BypassCVSS 4.3

Symfony 2.3.19 through 2.3.28, 2.4.9 through 2.4.10, 2.5.4 through 2.5.11, and 2.6.0 through 2.6.7, when ESI or SSI support enabled, does not check if the _controller attribute is set, which allows remote attackers to bypass URL signing and security rules by including (1) no hash or (2) an invalid hash in a request to /_fragment in the HttpKernel component.

Impact

Successful exploitation of this vulnerability could allow an attacker to bypass authentication and gain unauthorized access to the affected system.

Remediation

Apply the latest security patches or upgrade to a non-vulnerable version of Symfony.

WeaknessesCWE-284
AuthorsELSFA7110, meme-lord
Template tagscve2015cvesymfonyrcesensiolabsvuln
CVSS vector: CVSS:2.0/AV:N/AC:M/Au:N/C:N/I:P/A:N
CPE: cpe:2.3:a:sensiolabs:symfony:2.3.19:*:*:*:*:*:*:*
Shodan: cpe:"cpe:2.3:a:sensiolabs:symfony"

Source: ProjectDiscovery

References

11