CVE-2018-11408
Summary
| CVE | CVE-2018-11408 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-06-13 16:29:00 UTC |
| Updated | 2023-11-07 02:51:00 UTC |
| Description | The security handlers in the Security component in Symfony in 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x before 4.0.11 have an Open redirect vulnerability when security.http_utils is inlined by a container. NOTE: this issue exists because of an incomplete fix for CVE-2017-16652. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| CVE-2018-11408: Open redirect vulnerability on security handlers (Symfony Blog) |
CONFIRM |
symfony.com |
Vendor Advisory |
| [SECURITY] [DLA 1707-1] symfony security update |
MLIST |
lists.debian.org |
Third Party Advisory |
| [SECURITY] Fedora 28 Update: php-symfony3-3.4.11-1.fc28 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 28 Update: php-symfony3-3.4.11-1.fc28 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
Third Party Advisory |
| [SECURITY] Fedora 28 Update: php-symfony4-4.0.11-1.fc28 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 28 Update: php-symfony4-4.0.11-1.fc28 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
Third Party Advisory |
| [SECURITY] Fedora 28 Update: php-symfony-2.8.41-1.fc28 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
Third Party Advisory |
| [SECURITY] Fedora 28 Update: php-symfony-2.8.41-1.fc28 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 994762 PHP (Composer) Security Update for symfony/symfony (GHSA-7hwc-2cq4-6x2w)