CVE Vulnerabilities

CVE-2012-6432

Published: Dec 27, 2012 | Modified: Dec 27, 2012
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Symfony 2.0.x before 2.0.20, 2.1.x before 2.1.5, and 2.2-dev, when the internal routes configuration is enabled, allows remote attackers to access arbitrary services via vectors involving a URI beginning with a /_internal substring.

Affected Software

Name Vendor Start Version End Version
Symfony Sensiolabs 2.0.0 (including) 2.0.0 (including)
Symfony Sensiolabs 2.0.1 (including) 2.0.1 (including)
Symfony Sensiolabs 2.0.2 (including) 2.0.2 (including)
Symfony Sensiolabs 2.0.3 (including) 2.0.3 (including)
Symfony Sensiolabs 2.0.4 (including) 2.0.4 (including)
Symfony Sensiolabs 2.0.5 (including) 2.0.5 (including)
Symfony Sensiolabs 2.0.6 (including) 2.0.6 (including)
Symfony Sensiolabs 2.0.7 (including) 2.0.7 (including)
Symfony Sensiolabs 2.0.8 (including) 2.0.8 (including)
Symfony Sensiolabs 2.0.9 (including) 2.0.9 (including)
Symfony Sensiolabs 2.0.10 (including) 2.0.10 (including)
Symfony Sensiolabs 2.0.11 (including) 2.0.11 (including)
Symfony Sensiolabs 2.0.12 (including) 2.0.12 (including)
Symfony Sensiolabs 2.0.13 (including) 2.0.13 (including)
Symfony Sensiolabs 2.0.14 (including) 2.0.14 (including)
Symfony Sensiolabs 2.0.15 (including) 2.0.15 (including)
Symfony Sensiolabs 2.0.16 (including) 2.0.16 (including)
Symfony Sensiolabs 2.0.17 (including) 2.0.17 (including)
Symfony Sensiolabs 2.0.18 (including) 2.0.18 (including)
Symfony Sensiolabs 2.0.19 (including) 2.0.19 (including)
Symfony Sensiolabs 2.0.20 (including) 2.0.20 (including)

References