{"id":"GHSA-r7p7-qr7p-2rrf","summary":"Symfony Open Redirect","details":"An issue was discovered in Symfony 2.7.x before 2.7.38, 2.8.x before 2.8.31, 3.2.x before 3.2.14, and 3.3.x before 3.3.13. `DefaultAuthenticationSuccessHandler` or `DefaultAuthenticationFailureHandler` takes the content of the `_target_path` parameter and generates a redirect response, but no check is performed on the path, which could be an absolute URL to an external domain. This Open redirect vulnerability can be exploited for example to mount effective phishing attacks.","aliases":["CVE-2017-16652"],"modified":"2024-02-07T10:00:34.726241Z","published":"2022-05-14T01:21:36Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2023-07-26T19:56:19Z","nvd_published_at":"2018-06-13T16:29:00Z","cwe_ids":["CWE-601"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2017-16652"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/security-http/CVE-2017-16652.yaml"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/security/CVE-2017-16652.yaml"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/symfony/CVE-2017-16652.yaml"},{"type":"PACKAGE","url":"https://github.com/symfony/symfony"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2019/03/msg00009.html"},{"type":"WEB","url":"https://symfony.com/blog/cve-2017-16652-open-redirect-vulnerability-on-security-handlers"},{"type":"WEB","url":"https://symfony.com/cve-2017-16652"}],"affected":[{"package":{"name":"symfony/symfony","ecosystem":"Packagist","purl":"pkg:composer/symfony/symfony"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.7.0"},{"fixed":"2.7.38"}]}],"versions":["v2.7.0","v2.7.1","v2.7.10","v2.7.11","v2.7.12","v2.7.13","v2.7.14","v2.7.15","v2.7.16","v2.7.17","v2.7.18","v2.7.19","v2.7.2","v2.7.20","v2.7.21","v2.7.22","v2.7.23","v2.7.24","v2.7.25","v2.7.26","v2.7.27","v2.7.28","v2.7.29","v2.7.3","v2.7.30","v2.7.31","v2.7.32","v2.7.33","v2.7.34","v2.7.35","v2.7.36","v2.7.37","v2.7.4","v2.7.5","v2.7.6","v2.7.7","v2.7.8","v2.7.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-r7p7-qr7p-2rrf/GHSA-r7p7-qr7p-2rrf.json"}},{"package":{"name":"symfony/symfony","ecosystem":"Packagist","purl":"pkg:composer/symfony/symfony"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.8.0"},{"fixed":"2.8.31"}]}],"versions":["v2.8.0","v2.8.1","v2.8.10","v2.8.11","v2.8.12","v2.8.13","v2.8.14","v2.8.15","v2.8.16","v2.8.17","v2.8.18","v2.8.19","v2.8.2","v2.8.20","v2.8.21","v2.8.22","v2.8.23","v2.8.24","v2.8.25","v2.8.26","v2.8.27","v2.8.28","v2.8.29","v2.8.3","v2.8.30","v2.8.4","v2.8.5","v2.8.6","v2.8.7","v2.8.8","v2.8.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-r7p7-qr7p-2rrf/GHSA-r7p7-qr7p-2rrf.json"}},{"package":{"name":"symfony/symfony","ecosystem":"Packagist","purl":"pkg:composer/symfony/symfony"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.2.0"},{"fixed":"3.2.14"}]}],"versions":["v3.2.0","v3.2.1","v3.2.10","v3.2.11","v3.2.12","v3.2.13","v3.2.2","v3.2.3","v3.2.4","v3.2.5","v3.2.6","v3.2.7","v3.2.8","v3.2.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-r7p7-qr7p-2rrf/GHSA-r7p7-qr7p-2rrf.json"}},{"package":{"name":"symfony/symfony","ecosystem":"Packagist","purl":"pkg:composer/symfony/symfony"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.3.0"},{"fixed":"3.3.13"}]}],"versions":["v3.3.0","v3.3.1","v3.3.10","v3.3.11","v3.3.12","v3.3.2","v3.3.3","v3.3.4","v3.3.5","v3.3.6","v3.3.7","v3.3.8","v3.3.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-r7p7-qr7p-2rrf/GHSA-r7p7-qr7p-2rrf.json"}},{"package":{"name":"symfony/security-http","ecosystem":"Packagist","purl":"pkg:composer/symfony/security-http"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.7.0"},{"fixed":"2.7.38"}]}],"versions":["v2.7.0","v2.7.1","v2.7.10","v2.7.11","v2.7.12","v2.7.13","v2.7.14","v2.7.15","v2.7.16","v2.7.17","v2.7.18","v2.7.19","v2.7.2","v2.7.20","v2.7.21","v2.7.22","v2.7.23","v2.7.24","v2.7.25","v2.7.26","v2.7.27","v2.7.28","v2.7.29","v2.7.3","v2.7.30","v2.7.31","v2.7.32","v2.7.33","v2.7.34","v2.7.35","v2.7.36","v2.7.37","v2.7.4","v2.7.5","v2.7.6","v2.7.7","v2.7.8","v2.7.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-r7p7-qr7p-2rrf/GHSA-r7p7-qr7p-2rrf.json"}},{"package":{"name":"symfony/security-http","ecosystem":"Packagist","purl":"pkg:composer/symfony/security-http"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.8.0"},{"fixed":"2.8.31"}]}],"versions":["v2.8.0","v2.8.1","v2.8.10","v2.8.11","v2.8.12","v2.8.13","v2.8.14","v2.8.15","v2.8.16","v2.8.17","v2.8.18","v2.8.19","v2.8.2","v2.8.20","v2.8.21","v2.8.22","v2.8.23","v2.8.24","v2.8.25","v2.8.26","v2.8.27","v2.8.28","v2.8.29","v2.8.3","v2.8.30","v2.8.4","v2.8.5","v2.8.6","v2.8.7","v2.8.8","v2.8.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-r7p7-qr7p-2rrf/GHSA-r7p7-qr7p-2rrf.json"}},{"package":{"name":"symfony/security-http","ecosystem":"Packagist","purl":"pkg:composer/symfony/security-http"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.2.0"},{"fixed":"3.2.14"}]}],"versions":["v3.2.0","v3.2.1","v3.2.10","v3.2.11","v3.2.12","v3.2.13","v3.2.2","v3.2.3","v3.2.4","v3.2.5","v3.2.6","v3.2.7","v3.2.8","v3.2.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-r7p7-qr7p-2rrf/GHSA-r7p7-qr7p-2rrf.json"}},{"package":{"name":"symfony/security-http","ecosystem":"Packagist","purl":"pkg:composer/symfony/security-http"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.3.0"},{"fixed":"3.3.13"}]}],"versions":["v3.3.0","v3.3.1","v3.3.10","v3.3.11","v3.3.12","v3.3.2","v3.3.3","v3.3.4","v3.3.5","v3.3.6","v3.3.7","v3.3.8","v3.3.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-r7p7-qr7p-2rrf/GHSA-r7p7-qr7p-2rrf.json"}},{"package":{"name":"symfony/security","ecosystem":"Packagist","purl":"pkg:composer/symfony/security"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.7.0"},{"fixed":"2.7.38"}]}],"versions":["v2.7.0","v2.7.1","v2.7.10","v2.7.11","v2.7.12","v2.7.13","v2.7.14","v2.7.15","v2.7.16","v2.7.17","v2.7.18","v2.7.19","v2.7.2","v2.7.20","v2.7.21","v2.7.22","v2.7.23","v2.7.24","v2.7.25","v2.7.26","v2.7.27","v2.7.28","v2.7.29","v2.7.3","v2.7.30","v2.7.31","v2.7.32","v2.7.33","v2.7.34","v2.7.35","v2.7.36","v2.7.37","v2.7.4","v2.7.5","v2.7.6","v2.7.7","v2.7.8","v2.7.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-r7p7-qr7p-2rrf/GHSA-r7p7-qr7p-2rrf.json"}},{"package":{"name":"symfony/security","ecosystem":"Packagist","purl":"pkg:composer/symfony/security"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.8.0"},{"fixed":"2.8.31"}]}],"versions":["v2.8.0","v2.8.1","v2.8.10","v2.8.11","v2.8.12","v2.8.13","v2.8.14","v2.8.15","v2.8.16","v2.8.17","v2.8.18","v2.8.19","v2.8.2","v2.8.20","v2.8.21","v2.8.22","v2.8.23","v2.8.24","v2.8.25","v2.8.26","v2.8.27","v2.8.28","v2.8.29","v2.8.3","v2.8.30","v2.8.4","v2.8.5","v2.8.6","v2.8.7","v2.8.8","v2.8.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-r7p7-qr7p-2rrf/GHSA-r7p7-qr7p-2rrf.json"}},{"package":{"name":"symfony/security","ecosystem":"Packagist","purl":"pkg:composer/symfony/security"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.2.0"},{"fixed":"3.2.14"}]}],"versions":["v3.2.0","v3.2.1","v3.2.10","v3.2.11","v3.2.12","v3.2.13","v3.2.2","v3.2.3","v3.2.4","v3.2.5","v3.2.6","v3.2.7","v3.2.8","v3.2.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-r7p7-qr7p-2rrf/GHSA-r7p7-qr7p-2rrf.json"}},{"package":{"name":"symfony/security","ecosystem":"Packagist","purl":"pkg:composer/symfony/security"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.3.0"},{"fixed":"3.3.13"}]}],"versions":["v3.3.0","v3.3.1","v3.3.10","v3.3.11","v3.3.12","v3.3.2","v3.3.3","v3.3.4","v3.3.5","v3.3.6","v3.3.7","v3.3.8","v3.3.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-r7p7-qr7p-2rrf/GHSA-r7p7-qr7p-2rrf.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}