Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
🐘
🐘 Packagist
Not in CISA KEV
HIGH severity

CVE-2014-4931 — symfony/framework-bundle

HIGHFix: symfony/symfony@06a80fb

CVE-2014-4931 is a high-severity (CVSS 7.5) vulnerability in symfony/framework-bundle. A fix is available for symfony/framework-bundle — see the affected versions and patch details below.

Code injection in the way Symfony implements translation caching in FrameworkBundle

Published
May 30, 2024
Updated
May 30, 2024
Affected
6 pkgs
Patched
6 / 6
Exploits
None indexed
Exploitation data as of May 30, 2024 · OSV.dev, FIRST.org (EPSS)

Real-World Exposure

6 pkgs affected
🐘symfony/framework-bundle🐘symfony/framework-bundle🐘symfony/framework-bundle🐘symfony/symfony🐘symfony/symfony🐘symfony/symfony

Real-time download stats are indexed for npm and PyPI packages. This vulnerability affects Packagist packages — download data is not available via public APIs for these ecosystems.

Description

When investigating issue #11093, Jeremy Derussé found a serious code injection issue in the way Symfony implements translation caching in FrameworkBundle.

  • Your Symfony application is vulnerable if you meet the following conditions:

  • You are using the Symfony translation system from FrameworkBundle (so basically if you are using Symfony full-stack -- you are not affected if you are using the Translation component with Silex for instance); You don't sanitize locales coming from a URL (any route with a _locale argument for instance):

When vulnerable, an attacker can submit a non-valid locale value that can contain some PHP code that will be executed by Symfony. That's because the locale value is dumped into a PHP file generated in the cache without being sanitized first.

Affected Packages

6 total 6 fixed
EcosystemPackageVulnerable rangeFix
🐘Packagistsymfony/framework-bundle≥ 2.0.0&&< 2.3.182.3.18composer require symfony/framework-bundle:^2.3.18
🐘Packagistsymfony/framework-bundle≥ 2.4.0&&< 2.4.82.4.8composer require symfony/framework-bundle:^2.4.8
🐘Packagistsymfony/framework-bundle≥ 2.5.0&&< 2.5.22.5.2composer require symfony/framework-bundle:^2.5.2
🐘Packagistsymfony/symfony≥ 2.0.0&&< 2.3.192.3.19composer require symfony/symfony:^2.3.19
🐘Packagistsymfony/symfony≥ 2.4.0&&< 2.4.92.4.9composer require symfony/symfony:^2.4.9
🐘Packagistsymfony/symfony≥ 2.5.0&&< 2.5.42.5.4composer require symfony/symfony:^2.5.4

Detection & mitigation playbook

Open-source dependency
  1. Detect

    Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for symfony/framework-bundle, including transitive dependencies — a direct dependency you never call can still pull in a vulnerable version.

  2. Fix

    Update symfony/framework-bundle to 2.3.18 or later, then make sure no transitive (indirect) dependency still pins the vulnerable range — O3 confirms CVE-2014-4931 is resolved across your whole dependency graph.

  3. Workarounds

    If you can't upgrade right away: gate or disable the affected feature, validate untrusted input at the boundary, and avoid passing attacker-controlled data into the vulnerable path. O3's runtime protection blocks exploitation in production as an interim safeguard until the upgrade lands.

  4. How O3 protects you

    O3 Security's impact-aware SCA analyses which vulnerable code paths your application actually calls, so a match like CVE-2014-4931 can be triaged on real exposure rather than presence alone.

Tailored to CVE-2014-4931. Runtime protection reduces exposure until a permanent patch is applied and verified — it complements patching, it doesn't replace it.

Frequently Asked Questions

When investigating issue [#11093](https://github.com/symfony/symfony/issues/11093), [Jeremy Derussé](https://connect.sensiolabs.com/profile/jderusse) found a serious code injection issue in the way Symfony implements translation caching in FrameworkBundle. - Your Symfony application is vulnerable if you meet the following conditions: - You are using the Symfony translation system from FrameworkBundle (so basically if you are using Symfony full-stack -- you are not affected if you are using the Translation component with Silex for instance); You don't sanitize locales coming from a URL (any r
O3 Security · Impact-Aware SCA

Is CVE-2014-4931 in your dependencies?

O3 Security finds CVE-2014-4931 across Packagist dependencies, including transitive ones, and its impact-aware SCA ranks findings by whether your code actually calls the vulnerable path.