peter bassill · operator
$ cve CVE-2019-18889 JSON

CVE-2019-18889

9.8
CRITICAL · CVSS 3.1 · EPSS 33.2% (pctl 98)

Patch early

EPSS 33.2% — above the 10% action threshold.

Description

An issue was discovered in Symfony 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4.3.7. Serializing certain cache adapter interfaces could result in remote code injection. This is related to symfony/cache.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS33.25% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-94
On CISA KEVno
Public exploitnone known
Published2019-11-21
Last modified2026-06-17

Affected (2)

VendorProduct
fedoraprojectfedora
sensiolabssymfony

References

→ the Explorer  ·  watch your stack  ·  NVD