CVE-2012-6432
EPSS 0.43%Symfony Access Control Vulnerability
發布日:2022/5/17修改日:2024/12/2
描述
Symfony 2.0.x before 2.0.20, 2.1.x before 2.1.5, and 2.2-dev, when the internal routes configuration is enabled, allows remote attackers to access arbitrary services via vectors involving a URI beginning with a `/_internal` substring.
受影響套件(1)
參考連結(5)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2012-6432
- PATCHhttps://github.com/symfony/symfony
- WEBhttps://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/symfony/CVE-2012-6432.yaml
- WEBhttps://symfony.com/blog/security-release-symfony-2-0-20-and-2-1-5-released
- WEBhttp://symfony.com/blog/security-release-symfony-2-0-20-and-2-1-5-released