Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, Symfony\Component\Yaml\Parser::cleanup() used regular expressions with overlapping quantifiers for YAML directive, comment, and document marker cleanup, allowing crafted input to make parsing hang for an arbitrarily long time. This issue is fixed in versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XSensiolabs Symfony
APPSensiolabs< 5.4.526.0.0 – 6.4.40 (excl.)7.0.0 – 7.4.12 (excl.)8.0.0 – 8.0.12 (excl.)
Related vulnerabilities
Symfony X509Authenticator — obejście uwierzytelniania przez błędny regex DN
Symfony VarExporter — nieprawidłowe escapowanie umożliwia RCE
Symfony: zdalne wykonanie kodu przez serializację adaptera cache
Nieprawidłowa kontrola dostępu w komponencie Password validator — Symfony
SQL Injection i RCE w Symfony przez niezwalidowane identyfikatory serwisów