Vulnerability Bulletins |
DSA-3276 symfony - security update |
|
| Affected software | Debian |
|
Jakub Zalas discovered that Symfony, a framework to create websites andweb applications, was vulnerable to restriction bypass. It wasaffecting applications with ESI or SSI support enabled, that use theFragmentListener. A malicious user could call any controller via the/_fragment path by providing an invalid hash in the URL (or removingit), bypassing URL signing and security rules. More info: https://www.debian.org/security/2015/dsa-3276 |
|






