Description
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 7.1.0 until 7.4.12 and 8.0.12, Cas2Handler builds the CAS service parameter from Request::getSchemeAndHttpHost(), which reflects an attacker-controlled Host header when framework.trusted_hosts is not configured; an attacker controlling another application registered with the same CAS server can replay a victim ticket against the Symfony application and authenticate as the victim. This issue is fixed in versions 7.4.12 and 8.0.12.
Mitigation
Minimal update. May introduce new vulnerabilities or breaking changes.
|
 packagist | | >=7.1.0 <7.4.12 || >=8.0.0 <8.0.12 | 7.4.12, 8.0.12 |
 packagist | | >=7.1.0 <7.4.12 || >=8.0.0 <8.0.12 | 7.4.12, 8.0.12 |
 debian 14 | | =6.4.21+dfsg-2 || =6.4.24+dfsg-1 || =6.4.25+dfsg-1 || =7.0.4+dfsg-1 || =7.0.5+dfsg-1 || =7.0.6+dfsg-1 || =7.0.7+dfsg-1 || =7.1.0~beta1+dfsg-1 || =7.1.0~rc1+dfsg-1 || =7.1.2+dfsg-1 || =7.1.3+dfsg-1 || =7.1.4+dfsg-1 || =7.1.5+dfsg-1 || =7.2.0~beta1+dfsg-1 || =7.2.0~beta2+dfsg-1 || =7.2.0~rc1+dfsg-1 || =7.2.1+dfsg-1 || =7.2.2+dfsg-1 || =7.2.3+dfsg-1 || =7.2.4+dfsg-1 || =7.2.5+dfsg-1 || =7.2.6-1 || =7.3.0+dfsg-1 || =7.3.0~beta1+dfsg-1 || =7.3.0~beta2+dfsg-1 || =7.3.0~rc1+dfsg-1 || =7.3.1+dfsg-1 || =7.3.2+dfsg-1 || =7.3.3+dfsg-1 || =7.3.4+dfsg-1 || =7.3.5-1 || =7.4.0+dfsg-1 || =7.4.0+dfsg-2 || =7.4.0~beta1-1 || =7.4.0~beta1-2 || =7.4.0~beta2+dfsg-1 || =7.4.0~beta2+dfsg-2 || =7.4.0~beta2+dfsg-3 || =7.4.0~rc1+dfsg-1 || =7.4.0~rc2+dfsg-1 || =7.4.0~rc3+dfsg-1 || =7.4.10+dfsg-1 || =7.4.2+dfsg-1 || =7.4.2+dfsg-2 || =7.4.3+dfsg-1 || =7.4.4+dfsg-1 || =7.4.5+dfsg-1 || =7.4.6+dfsg-1 || =7.4.6+dfsg-2 || =7.4.7+dfsg-1 || =7.4.8+dfsg-1 || =7.4.9+dfsg-1 || >=0 <7.4.12+dfsg-1 | 7.4.12+dfsg-1 |