CVE-2019-10912
Summary
| CVE | CVE-2019-10912 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-05-16 22:29:00 UTC |
| Updated | 2023-11-07 03:02:00 UTC |
| Description | In Symfony before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, it is possible to cache objects that may contain bad user input. On serialization or unserialization, this could result in the deletion of files that the current user has access to. This is related to symfony/cache and symfony/phpunit-bridge. |
Risk And Classification
Problem Types: CWE-502
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Sensiolabs | Symfony | All | All | All | All |
| Application | Sensiolabs | Symfony | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [SECURITY] Fedora 30 Update: php-symfony3-3.4.26-1.fc30 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| [SECURITY] Fedora 29 Update: php-symfony3-3.4.26-1.fc29 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| [SECURITY] Fedora 30 Update: php-symfony4-4.2.7-2.fc30 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| [SECURITY] Fedora 29 Update: php-symfony-2.8.51-1.fc29 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| [SECURITY] Fedora 30 Update: php-symfony-2.8.51-1.fc30 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| [SECURITY] Fedora 28 Update: php-symfony3-3.4.26-1.fc28 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| [SECURITY] Fedora 30 Update: php-symfony-2.8.51-1.fc30 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| Possible deserialization side-effects in symfony/cache | CONFIRM | typo3.org | |
| [SECURITY] Fedora 29 Update: php-symfony4-4.1.12-1.fc29 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| [SECURITY] Fedora 29 Update: php-symfony-2.8.51-1.fc29 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| Prevent destructors with side-effects from being unserialized · symfony/symfony@4fb9752 · GitHub | CONFIRM | github.com | Patch, Third Party Advisory |
| [SECURITY] Fedora 30 Update: php-symfony4-4.2.7-2.fc30 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| [SECURITY] Fedora 29 Update: php-symfony3-3.4.26-1.fc29 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| [SECURITY] Fedora 29 Update: php-symfony4-4.1.12-1.fc29 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| [SECURITY] Fedora 30 Update: php-symfony3-3.4.26-1.fc30 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| [SECURITY] Fedora 28 Update: php-symfony3-3.4.26-1.fc28 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| Bugtraq: [SECURITY] [DSA 4441-1] symfony security update | BUGTRAQ | seclists.org | |
| CVE-2019-10912: Prevent destructors with side-effects from being unserialized (Symfony Blog) | CONFIRM | symfony.com | Third Party Advisory |
| [SECURITY] Fedora 28 Update: php-symfony-2.8.51-1.fc28 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| Debian -- Security Information -- DSA-4441-1 symfony | DEBIAN | www.debian.org | |
| [SECURITY] Fedora 28 Update: php-symfony-2.8.51-1.fc28 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.