{"id":"CVE-2020-15094","details":"In Symfony before versions 4.4.13 and 5.1.5, the CachingHttpClient class from the HttpClient Symfony component relies on the HttpCache class to handle requests. HttpCache uses internal headers like X-Body-Eval and X-Body-File to control the restoration of cached responses. The class was initially written with surrogate caching and ESI support in mind (all HTTP calls come from a trusted backend in that scenario). But when used by CachingHttpClient and if an attacker can control the response for a request being made by the CachingHttpClient, remote code execution is possible. This has been fixed in versions 4.4.13 and 5.1.5.","aliases":["BIT-symfony-2020-15094","GHSA-754h-5r27-7x3r"],"modified":"2026-08-11T03:46:13.076681417Z","published":"2020-09-02T18:15:11.187Z","database_specific":{"unresolved_ranges":[{"source":"CPE_STRING","vendor_product":"fedoraproject:fedora","cpes":["cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*","cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"32"},{"last_affected":"32"},{"introduced":"33"},{"last_affected":"33"}]}]},"references":[{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HNGUWOEETOFVH4PN3I3YO4QZHQ4AUKF3/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VAQJXAKWPMWB7OL6QPG2ZSEQZYYPU5RC/"},{"type":"ADVISORY","url":"https://github.com/symfony/symfony/security/advisories/GHSA-754h-5r27-7x3r"},{"type":"ADVISORY","url":"https://packagist.org/packages/symfony/http-kernel"},{"type":"ADVISORY","url":"https://packagist.org/packages/symfony/symfony"},{"type":"FIX","url":"https://github.com/symfony/symfony/commit/d9910e0b33a2e0f993abff41c6fbc86951b66d78"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/symfony/http-client","events":[{"introduced":"233f73babb157deac7289119aa3d0e871bac8def"},{"fixed":"1d06c290f2875cc87ecf64ecd33e62f857530ce4"},{"introduced":"63342eabdc6fc6c12e6b18506a207d16687aa33f"},{"fixed":"21c4372e9cd2305313f4d4792d7b9fa7c25ade53"}],"database_specific":{"cpe":"cpe:2.3:a:sensiolabs:httpclient:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"4.4.0"},{"fixed":"4.4.13"},{"introduced":"5.1.0"},{"fixed":"5.1.5"}],"source":"CPE_RANGE"}}],"versions":["v5.1.4","v4.4.12","v5.1.3","v4.4.11","v5.1.2","v5.1.1","v4.4.10","v5.1.0","v4.4.9","v4.4.8","v4.4.7","v4.4.6","v4.4.5","v4.4.4","v4.4.3","v4.4.2","v4.4.1","v4.4.0"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2020-15094.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/symfony/security-http","events":[{"introduced":"e49361b75e9acbc029b35ae4ba957e712137286b"},{"fixed":"473da00f1244ead079619628a3781622877efdd3"},{"introduced":"6a785d9a0deeb401d7ae540fd0492aca4e6b894e"},{"fixed":"7741021221548e2b5768ec0cf502c91b6c55b209"}],"database_specific":{"source":"CPE_RANGE","cpe":"cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"4.4.0"},{"fixed":"4.4.13"},{"introduced":"5.1.0"},{"fixed":"5.1.5"}]}}],"versions":["v5.1.3","v4.4.9","v4.4.11","v4.4.10","v5.1.2","v5.1.1","v5.1.0","v4.4.8","v4.4.7","v4.4.6","v4.4.5","v4.4.4","v4.4.3","v4.4.2","v4.4.1","v4.4.0"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2020-15094.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/symfony/symfony","events":[{"introduced":"625a4dbfdafcb8cea8ff90a62b9c24b28694938d"},{"fixed":"9b8314080fb15e84e030f94488d9e1fa17adb846"},{"introduced":"729e21c65356880bd9488588e726aa8735dcb52f"},{"fixed":"31b6a95fc288617ccfa27aa819d30c0c2201416a"},{"fixed":"d9910e0b33a2e0f993abff41c6fbc86951b66d78"}],"database_specific":{"extracted_events":[{"introduced":"4.4.0"},{"fixed":"4.4.13"},{"introduced":"5.1.0"},{"fixed":"5.1.5"}],"source":["CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*"}}],"versions":["v5.1.4","v4.4.12","v5.1.3","v4.4.11","v4.4.10","v5.1.2","v5.1.1","v5.1.0","v4.4.9","v4.4.8","v4.4.7","v4.4.6","v4.4.5","v4.4.4","v4.4.3","v4.4.2","v4.4.1","v4.4.0"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2020-15094.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}