{"id":"CVE-2018-19790","aliases":["GHSA-89r2-5g34-2g47"],"url":"https://o3.security/vulnerability/CVE-2018-19790","summary":"Symfony Open Redirect","details":"An open redirect was discovered in Symfony 2.7.x before 2.7.50, 2.8.x before 2.8.49, 3.x before 3.4.20, 4.0.x before 4.0.15, 4.1.x before 4.1.9 and 4.2.x before 4.2.1. By using backslashes in the `_failure_path` input field of login forms, an attacker can work around the redirection target restrictions and effectively redirect the user to any domain after login.","published":"2018-12-18T22:29:05.040Z","modified":"2026-08-07T11:48:11.769566684Z","cvss":{"score":6.1,"severity":"MEDIUM","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"symfony/security-http","fixedVersion":"2.7.50"},{"ecosystem":"Packagist","name":"symfony/security-http","fixedVersion":"2.8.49"},{"ecosystem":"Packagist","name":"symfony/security-http","fixedVersion":"3.4.20"},{"ecosystem":"Packagist","name":"symfony/security-http","fixedVersion":"4.0.15"},{"ecosystem":"Packagist","name":"symfony/security-http","fixedVersion":"4.1.9"},{"ecosystem":"Packagist","name":"symfony/security-http","fixedVersion":"4.2.1"},{"ecosystem":"Packagist","name":"symfony/security","fixedVersion":"2.7.50"},{"ecosystem":"Packagist","name":"symfony/security","fixedVersion":"2.8.49"},{"ecosystem":"Packagist","name":"symfony/security","fixedVersion":"3.4.19"},{"ecosystem":"Packagist","name":"symfony/security","fixedVersion":"4.0.15"},{"ecosystem":"Packagist","name":"symfony/security","fixedVersion":"4.1.9"},{"ecosystem":"Packagist","name":"symfony/security","fixedVersion":"4.2.1"},{"ecosystem":"Packagist","name":"symfony/symfony","fixedVersion":"2.7.50"},{"ecosystem":"Packagist","name":"symfony/symfony","fixedVersion":"2.8.49"},{"ecosystem":"Packagist","name":"symfony/symfony","fixedVersion":"3.4.20"},{"ecosystem":"Packagist","name":"symfony/symfony","fixedVersion":"4.0.15"},{"ecosystem":"Packagist","name":"symfony/symfony","fixedVersion":"4.1.9"}],"fix":null,"references":[{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4TD3E7FZIXLVFG3SMFJPDEKPZ26TJOW7/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JZMRJ7VTHCY5AZK24G4QGX36RLUDTDKE/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OA4WVFN5FYPIXAPLWZI6N425JHHDSWAZ/"},{"type":"WEB","url":"https://seclists.org/bugtraq/2019/May/21"},{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/106249"},{"type":"ADVISORY","url":"https://lists.debian.org/debian-lts-announce/2019/03/msg00009.html"},{"type":"ADVISORY","url":"https://www.debian.org/security/2019/dsa-4441"},{"type":"FIX","url":"https://symfony.com/blog/cve-2018-19790-open-redirect-vulnerability-when-using-security-http"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T11:48:11.769566684Z"}}