
Cloud Vulnerability DB
A community-led vulnerabilities database
The XMLEncoder component of Symfony 2.0.x contains a critical security vulnerability (GHSA-mmcv-fvq8-r9x3) that fails to disable external entities when parsing XML. This vulnerability affects Symfony versions 2.0.0 to 2.0.11 and was discovered and reported by Sense of Security on February 24, 2012. The issue impacts the Serializer component, which is used for deserializing objects or as part of client/server API functionality (Symfony Blog, GitHub Advisory).
The vulnerability has been assigned a Critical severity rating with a CVSS score of 9.8. The attack vector is network-based with low attack complexity, requiring no privileges or user interaction. The vulnerability allows for unauthorized access with high impact on confidentiality, integrity, and availability. The issue specifically relates to the XMLEncoder component's failure to properly handle external entities during XML parsing, which could lead to security breaches (GitHub Advisory).
When exploited, this vulnerability allows attackers to include arbitrary files from the file system through external entities. For example, attackers could potentially access sensitive system files such as /etc/passwd in base64 encoded form through XML deserialization (Symfony Blog).
The vulnerability is easily exploitable through XML deserialization. A proof of concept exploit was provided demonstrating how an attacker could use the Serializer component with XMLEncoder to access system files. The exploit requires minimal setup and can be executed through standard XML parsing operations (Symfony Blog).
The vulnerability was patched in Symfony version 2.0.11. Users are strongly advised to upgrade to this version or apply the appropriate security patch. The fix, implemented by Jordi Boggiano, involves properly disabling external entity loading during XML parsing. For users unable to upgrade immediately, the patch can be applied directly to the affected components (Symfony Blog, GitHub Commit).
The Symfony team demonstrated rapid response to the security issue, releasing the patch on the same day it was reported. The community praised the quick response time and transparency in handling the security vulnerability. The fix was well-received by the developer community, with several community members acknowledging the swift action taken to address the security concern (Symfony Blog).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."