
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2020-5255 is a security vulnerability affecting Symfony HttpFoundation component versions 4.4.0 to 4.4.6 and 5.0.0 to 5.0.6. The vulnerability was discovered and disclosed on March 30, 2020. When a Response does not contain a Content-Type header, Symfony falls back to the format defined in the Accept header of the request, which could lead to potential security issues (Symfony Blog).
The vulnerability occurs when a Response does not contain a Content-Type header, causing Symfony to use the format defined in the Accept header of the request as a fallback. This behavior can create a mismatch between the response's content and Content-Type header. The issue has been assigned a moderate severity rating (GitHub Advisory).
When the response is cached, this vulnerability can lead to cache poisoning where the cached format is not the correct one, potentially causing corrupted cache entries. This mismatch between content and Content-Type header can affect the way content is interpreted by clients (Symfony Blog).
The issue has been fixed in Symfony versions 4.4.7 and 5.0.7. The fix involves preventing Symfony from using the Accept header to guess the Content-Type. Users should upgrade to these patched versions or later to resolve the vulnerability (Symfony Blog).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."