CVE-2019-10910 PUBLISHED

In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, when service ids allow user input, this could allow for SQL Injection and remote code execution. This is related to symfony/dependency-injection.

EPSS 12.30% · 93.8th percentile

Risk Scores

EPSS Score
12.30%
93.8th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:18.04:LTSsymfony3.4.6+dfsg-1ubuntu0.1+esm2, 0, 2.8.7+dfsg-1.3ubuntu1
Ubuntu:16.04:LTSsymfony2.7.1+dfsg-1, 2.7.5+dfsg-1, 2.7.9+dfsg-1

Timeline

References

Open in Interactive Console →