CVE-2015-4050: Improper Access Control
(updated )
FragmentListener in the HttpKernel component in Symfony, when ESI or SSI support enabled, does not check if the _controller
attribute is set, which allows remote attackers to bypass URL signing and security rules by including (1) no hash or (2) an invalid hash in a request to /_fragment
.
References
Detect and mitigate CVE-2015-4050 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →