CVE-2018-14774
unknown
CVSS v3
—
CVSS v2
—
VIR risk
—
Description
An issue was discovered in HttpKernel in Symfony 2.7.0 through 2.7.48, 2.8.0 through 2.8.43, 3.3.0 through 3.3.17, 3.4.0 through 3.4.13, 4.0.0 through 4.0.13, and 4.1.0 through 4.1.2. When using HttpCache, the values of the X-Forwarded-Host headers are implicitly set as trusted while this should be forbidden, leading to potential host header injection.
Predictions
Exploit likelihood
30%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2018-14774
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| debian | bookworm | fixed | 3.4.14+dfsg-1 |
| debian | bullseye | fixed | 3.4.14+dfsg-1 |
| debian | forky | fixed | 3.4.14+dfsg-1 |
| debian | sid | fixed | 3.4.14+dfsg-1 |
| debian | trixie | fixed | 3.4.14+dfsg-1 |
Package impact
| Ecosystem | Package | Vulnerable | Fixed |
|---|---|---|---|
| Packagist | symfony/symfony | >=2.7.0,<2.7.49 | 2.7.49 |
| Packagist | symfony/symfony | >=2.8.0,<2.8.44 | 2.8.44 |
| Packagist | symfony/symfony | >=3.3.0,<3.3.18 | 3.3.18 |
| Packagist | symfony/symfony | >=3.4.0,<3.4.14 | 3.4.14 |
| Packagist | symfony/symfony | >=4.0.0,<4.0.14 | 4.0.14 |
| Packagist | symfony/symfony | >=4.1.0,<4.1.3 | 4.1.3 |
References
- https://nvd.nist.gov/vuln/detail/CVE-2018-14774
- https://github.com/symfony/symfony/commit/725dee4cd8b4ccd52e335ae4b4522242cea9bd4a
- https://github.com/symfony/symfony/commit/7f912bbb78377c2ea331b3da28363435fbd91337
- https://github.com/symfony/symfony/commit/96504fb8c9f91204727d2930eb837473ce154956
- https://github.com/symfony/symfony/commit/974240e178bb01d734bf1df1ad5c3beba6a2f982
- https://github.com/symfony/symfony/commit/9cfcaba0bf71f87683510b5f47ebaac5f5d6a5ba
- https://github.com/symfony/symfony/commit/bcf5897bb1a99d4acae8bf7b73e81bfdeaac0922
- https://github.com/symfony/symfony
- https://symfony.com/blog/cve-2018-14774-possible-host-header-injection-when-using-httpcache
- https://security-tracker.debian.org/tracker/CVE-2018-14774
Verify integrity in audit chain (admin only). AS-IS.