VDB
CVE-2015-4050
CVE-2015-4050
REJECTED
FragmentListener in the HttpKernel component in Symfony 2.3.19 through 2.3.28, 2.4.9 through 2.4.10, 2.5.4 through 2.5.11, and 2.6.0 through 2.6.7, when ESI or SSI support enabled, does not check if the _controller attribute is set, which allows remote attackers to bypass URL signing and security rules by including (1) no hash or (2) an invalid hash in a request to /_fragment.
EPSS 8.27% · 94.6th percentile
Risk Scores
EPSS Score
8.27%
94.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu:18.04:LTS | symfony | 0, 2.8.7+dfsg-1.3ubuntu1, 3.4.3+dfsg-1ubuntu4 |
| Ubuntu:16.04:LTS | symfony | 2.7.9+dfsg-1, *, 2.7.9+dfsg-1ubuntu2 |
Timeline
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
- Sep 8, 2023 EPSS Score
- Oct 31, 2023 EPSS Score
- Feb 13, 2024 EPSS Score
- Apr 6, 2024 EPSS Score
References
- https://ubuntu.com/security/CVE-2015-4050 third-party-advisory
- http://symfony.com/blog/cve-2015-4050-esi-unauthorized-access third-party-advisory
- https://www.cve.org/CVERecord?id=CVE-2015-4050 third-party-advisory