Server side template injection In symfony/yaml
Description
Symfony Arbitrary PHP code Execution Symfony 2.0.x before 2.0.22, 2.1.x before 2.1.7, and 2.2.x remote attackers to execute arbitrary PHP code via a serialized PHP object to the (1) Yaml::parse or (2) Yaml\Parser::parse function, a different vulnerability than CVE-2013-1348.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
packagist | 2.0.22, 2.1.7, 2.2.0-beta2 | ||
packagist | 2.2.0-beta2, 2.0.22, 2.1.7 |
Aliases
1. 2. 3. 4.
References
1. 2. 3. 4. 5. 6.