CVE-2015-4050 describes an authentication bypass vulnerability in the FragmentListener component of Symfony versions 2.3.19-2.3.28, 2.4.9-2.4.10, 2.5.4-2.5.11, and 2.6.0-2.6.7, specifically when ESI or SSI support is enabled. This medium-severity vulnerability (CVSS 4.3) allows remote attackers to bypass URL signing and security rules by sending requests to /_fragment with missing or invalid hashes, leading to potential unauthorized access. While not listed in CISA's KEV catalog, there is a Nuclei template available for detection and it has garnered some community discussion and media coverage, indicating awareness and potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.3.19CPE matchmatch criteria | cpe:2.3:a:sensiolabs:symfony:2.3.19:*:*:*:*:*:*:* | ||
2.3.20CPE matchmatch criteria | cpe:2.3:a:sensiolabs:symfony:2.3.20:*:*:*:*:*:*:* | ||
2.3.21CPE matchmatch criteria | cpe:2.3:a:sensiolabs:symfony:2.3.21:*:*:*:*:*:*:* | ||
2.3.22CPE matchmatch criteria | cpe:2.3:a:sensiolabs:symfony:2.3.22:*:*:*:*:*:*:* | ||
2.3.23CPE matchmatch criteria | cpe:2.3:a:sensiolabs:symfony:2.3.23:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:N/I:P/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.