CVE-2018-11386

EUVD-2022-5068
An issue was discovered in the HttpFoundation component in Symfony 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x before 4.0.11. The PDOSessionHandler class allows storing sessions on a PDO connection. Under some configurations and with a well-crafted payload, it was possible to do a denial of service on a Symfony application without too much resources.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.9 MEDIUM
NETWORK
HIGH
NONE
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 77%
Affected Products (NVD)
VendorProductVersion
sensiolabssymfony
2.7.0 ≤
𝑥
< 2.7.48
sensiolabssymfony
2.8.0 ≤
𝑥
< 2.8.41
sensiolabssymfony
3.3.0 ≤
𝑥
< 3.3.17
sensiolabssymfony
3.4.0 ≤
𝑥
< 3.4.11
sensiolabssymfony
4.0.0 ≤
𝑥
< 4.0.11
debiandebian_linux
9.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
symfony
bookworm
5.4.23+dfsg-1+deb12u2
fixed
bullseye
4.4.19+dfsg-2+deb11u6
fixed
jessie
not-affected
sid
6.4.13+dfsg-1
fixed
trixie
6.4.13+dfsg-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
symfony
artful
ignored
bionic
Fixed 3.4.6+dfsg-1ubuntu0.1
released
trusty
dne
xenial
not-affected