Record summary

CVE-2019-18887 has a selected CVSS score of 8.1 (high).

Description

An issue was discovered in Symfony 2.8.0 through 2.8.50, 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4.3.7. The UriSigner was subject to timing attacks. This is related to symfony/http-kernel.

Description source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus
GitHub Advisory2.2.0 to < 2.8.52 · Fixed in 2.8.52affected
3.0.0 to < 3.4.35 · Fixed in 3.4.35affected
4.0.0 to < 4.2.12 · Fixed in 4.2.12affected
4.3.0 to < 4.3.8 · Fixed in 4.3.8affected
GitHub Advisory2.2.0 to < 2.8.52 · Fixed in 2.8.52affected
3.0.0 to < 3.4.35 · Fixed in 3.4.35affected
4.0.0 to < 4.2.12 · Fixed in 4.2.12affected
4.3.0 to < 4.3.8 · Fixed in 4.3.8affected

References

Showing 12 of 13