CVE-2018-14774: Improper Input Validation
(updated )
An issue was discovered in HttpKernel
in Symfony When using HttpCache
, the values of the X-Forwarded-Host
headers are implicitly set as trusted while this should be forbidden, leading to potential host header injection.
References
Detect and mitigate CVE-2018-14774 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →