CVE-2015-4050
Summary
| CVE | CVE-2015-4050 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2015-06-02 14:59:12 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | FragmentListener in the HttpKernel component in Symfony 2.3.19 through 2.3.28, 2.4.9 through 2.4.10, 2.5.4 through 2.5.11, and 2.6.0 through 2.6.7, when ESI or SSI support enabled, does not check if the _controller attribute is set, which allows remote attackers to bypass URL signing and security rules by including (1) no hash or (2) an invalid hash in a request to /_fragment. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:M/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Sensiolabs | Symfony | 2.3.19 | All | All | All |
| Application | Sensiolabs | Symfony | 2.3.20 | All | All | All |
| Application | Sensiolabs | Symfony | 2.3.21 | All | All | All |
| Application | Sensiolabs | Symfony | 2.3.22 | All | All | All |
| Application | Sensiolabs | Symfony | 2.3.23 | All | All | All |
| Application | Sensiolabs | Symfony | 2.3.24 | All | All | All |
| Application | Sensiolabs | Symfony | 2.3.25 | All | All | All |
| Application | Sensiolabs | Symfony | 2.3.26 | All | All | All |
| Application | Sensiolabs | Symfony | 2.3.27 | All | All | All |
| Application | Sensiolabs | Symfony | 2.3.28 | All | All | All |
| Application | Sensiolabs | Symfony | 2.4.10 | All | All | All |
| Application | Sensiolabs | Symfony | 2.4.9 | All | All | All |
| Application | Sensiolabs | Symfony | 2.5.10 | All | All | All |
| Application | Sensiolabs | Symfony | 2.5.11 | All | All | All |
| Application | Sensiolabs | Symfony | 2.5.4 | All | All | All |
| Application | Sensiolabs | Symfony | 2.5.5 | All | All | All |
| Application | Sensiolabs | Symfony | 2.5.6 | All | All | All |
| Application | Sensiolabs | Symfony | 2.5.7 | All | All | All |
| Application | Sensiolabs | Symfony | 2.5.8 | All | All | All |
| Application | Sensiolabs | Symfony | 2.5.9 | All | All | All |
| Application | Sensiolabs | Symfony | 2.6.0 | All | All | All |
| Application | Sensiolabs | Symfony | 2.6.1 | All | All | All |
| Application | Sensiolabs | Symfony | 2.6.3 | All | All | All |
| Application | Sensiolabs | Symfony | 2.6.4 | All | All | All |
| Application | Sensiolabs | Symfony | 2.6.5 | All | All | All |
| Application | Sensiolabs | Symfony | 2.6.6 | All | All | All |
| Application | Sensiolabs | Symfony | 2.6.7 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Debian -- Security Information -- DSA-3276-1 symfony | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| Symfony CVE-2015-4050 Unauthorized Access Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| CVE-2015-4050: ESI unauthorized access (Symfony Blog) | af854a3a-2127-422b-91ae-364da2661108 | symfony.com | Vendor Advisory |
| [SECURITY] Fedora 21 Update: php-symfony-2.5.12-1.fc21 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | |
| [SECURITY] Fedora 22 Update: php-symfony-2.5.12-1.fc22 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | |
| [SECURITY] Fedora 20 Update: php-symfony-2.5.12-1.fc20 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.