CVE-2020-5274

Source
https://cve.org/CVERecord?id=CVE-2020-5274
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-5274.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2020-5274
Aliases
Downstream
Related
Published
2020-03-30T20:15:19.633Z
Modified
2026-02-09T05:09:28.631906Z
Severity
  • 5.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

In Symfony before versions 5.0.5 and 4.4.5, some properties of the Exception were not properly escaped when the ErrorHandler rendered it stacktrace. In addition, the stacktrace were displayed even in a non-debug configuration. The ErrorHandler now escape alls properties of the exception, and the stacktrace is only display in debug configuration. This issue is patched in symfony/http-foundation versions 4.4.5 and 5.0.5

References

Affected packages

Git / github.com/symfony/security-http

Affected ranges

Affected versions

v3.*
v3.4.36
v3.4.37
v4.*
v4.3.10
v4.3.11
v4.3.9
v4.4.0
v4.4.1
v4.4.2
v4.4.3

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-5274.json"

Git / github.com/symfony/symfony

Affected versions

v3.*
v3.4.36
v3.4.37
v4.*
v4.3.10
v4.3.9
v4.4.0
v4.4.1
v4.4.2
v4.4.3
v5.*
v5.0.0
v5.0.1
v5.0.2
v5.0.3

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-5274.json"