Server side template injection In symfony/symfony
Description
Symphony Vulnerable to PHP Code Injection via YAML Parsing
The Yaml::parse function in Symfony 2.0.x before 2.0.22 remote attackers to execute arbitrary PHP code via a PHP file, a different vulnerability than CVE-2013-1397.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
packagist | 2.0.22 | ||
packagist | 2.0.22 |
Aliases
1. 2. 3. 4.
References
1. 2. 3. 4. 5. 6.