Race condition In symfony
Description
In Symfony before versions 4.4.7 and 5.0.7, when a Response does not contain a Content-Type header, affected versions of Symfony can fallback to the format defined in the Accept header of the request, leading to a possible mismatch between the response's content and Content-Type header. When the response is cached, this can prevent the use of the website by other users. This has been patched in versions 4.4.7 and 5.0.7.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
debian 11 | 4.4.8-1 | ||
debian 12 | 4.4.8-1 | ||
debian 13 | 4.4.8-1 | ||
packagist | 4.4.7, 5.0.7 | ||
packagist | 4.4.7, 5.0.7 | ||
debian 14 | 4.4.8-1 |
Aliases
1. 2. 3. 4. 5. 6. 7.
References
1. 2. 3. 4. 5. 6. 7.