CVE-2019-10910
In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, when service ids allow user input, this could allow for SQL Injection and remote code execution.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (5.95%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, when service ids allow user input, this could allow for SQL Injection and remote code execution. This is related to symfony/dependency-injection.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 5.95% probability · 93th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-89
- Affected
- sensiolabs/symfony · drupal/drupal
- Source
- cve@mitre.org
References
- https://github.com/symfony/symfony/commit/d2fb5893923292a1da7985f0b56960b5bb10737bPatch
- https://symfony.com/blog/cve-2019-10910-check-service-ids-are-validExploit, Third Party Advisory
- https://www.synology.com/security/advisory/Synology_SA_19_19Third Party Advisory
- https://github.com/symfony/symfony/commit/d2fb5893923292a1da7985f0b56960b5bb10737bPatch
- https://symfony.com/blog/cve-2019-10910-check-service-ids-are-validExploit, Third Party Advisory
- https://www.synology.com/security/advisory/Synology_SA_19_19Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.