漏洞描述
Symfony 2.3.19 through 2.3.28, 2.4.9 through 2.4.10, 2.5.4 through 2.5.11, and 2.6.0 through 2.6.7, when ESI or SSI support enabled, does not check if the _controller attribute is set, which allows remote attackers to bypass URL signing and security rules by including (1) no hash or (2) an invalid hash in a request to /_fragment in the HttpKernel component.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
symfony.comhttps://symfony.com/blog/cve-2015-4050-esi-unauthorized-access↗symfony.comhttp://symfony.com/blog/cve-2015-4050-esi-unauthorized-access↗www.debian.orghttp://www.debian.org/security/2015/dsa-3276↗nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2015-4050↗lists.fedoraproject.orghttp://lists.fedoraproject.org/pipermail/package-announce/2015-June/159513.html↗