ZeroHour

CVE-2019-18887

CVSS 3.1
8.1 high
EPSS
1%p70
Published
()
Modified
Description

An issue was discovered in Symfony 2.8.0 through 2.8.50, 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4.3.7. The UriSigner was subject to timing attacks. This is related to symfony/http-kernel.

Vendors
sensiolabsfedoraproject
Products
symfony, fedora
Weakness
CWE-203
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.