UBUNTU-CVE-2018-12040

Source
https://ubuntu.com/security/CVE-2018-12040
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2018/UBUNTU-CVE-2018-12040.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2018-12040
Withdrawn
2025-06-23T15:53:11Z
Published
2018-06-13T22:29:00Z
Modified
2018-06-13T22:29:00Z
Severity
  • 6.1 (Medium) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

** DISPUTED ** Reflected Cross-site scripting (XSS) vulnerability in the web profiler in SensioLabs Symfony 3.3.6 allows remote attackers to inject arbitrary web script or HTML via the "file" parameter, aka an _profiler/open?file= URI. NOTE: The vendor states "The XSS ... is in the web profiler, a tool that should never be deployed in production (so, we don't handle those issues as security issues)."

References

Affected packages

Ubuntu:Pro:16.04:LTS / symfony

Package

Name
symfony
Purl
pkg:deb/ubuntu/symfony

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*
2.7.1+dfsg-1
2.7.5+dfsg-1
2.7.9+dfsg-1
2.7.9+dfsg-1ubuntu2
2.7.10-0ubuntu2

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2018/UBUNTU-CVE-2018-12040.json"

Ubuntu:Pro:18.04:LTS / symfony

Package

Name
symfony
Purl
pkg:deb/ubuntu/symfony

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*
2.8.7+dfsg-1.3ubuntu1
3.*
3.4.3+dfsg-1ubuntu4
3.4.6+dfsg-1
3.4.6+dfsg-1ubuntu0.1
3.4.6+dfsg-1ubuntu0.1+esm1
3.4.6+dfsg-1ubuntu0.1+esm2

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2018/UBUNTU-CVE-2018-12040.json"