In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, when service ids allow user input, this could allow for SQL Injection and remote code execution. This is related to symfony/dependency-injection.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HDrupal
APPDrupal8.5.0 – 8.5.15 (excl.)8.6.0 – 8.6.15 (excl.)Sensiolabs Symfony
APPSensiolabs3.4.0 – 3.4.26 (excl.)2.7.0 – 2.7.51 (excl.)4.2.0 – 4.2.7 (excl.)4.1.0 – 4.1.12 (excl.)2.8.0 – 2.8.50 (excl.)
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
RCESQLi
CWE
References
Related vulnerabilities
CVE-2018-7602CRITICAL9.8⚠ KEVPL ✓same product
RCE w Drupal 7.x i 8.x — zdalne wykonanie kodu (Drupalgeddon2 follow-up)
CVE-2018-7600CRITICAL9.8⚠ KEVPL ✓same product
Drupalgeddon 2 — zdalne wykonanie kodu w Drupal (RCE)
CVE-2026-45063CRITICAL9.1PL ✓same product
Symfony X509Authenticator — obejście uwierzytelniania przez błędny regex DN
CVE-2024-55636CRITICAL9.8PL ✓same product
Deserialization podatności w Drupal Core umożliwiająca RCE (Object Injection)
CVE-2024-55637CRITICAL9.8PL ✓same product
Deserializacja niezaufanych danych w Drupal Core umożliwia RCE