{"id":"GHSA-vfm6-r2gc-pwww","aliases":[],"url":"https://o3.security/vulnerability/GHSA-vfm6-r2gc-pwww","summary":"Symfony2 security issue when the trust proxy mode is enabled","details":"An application is vulnerable if it uses the client IP address as returned by the Request::getClientIp() method for sensitive decisions like IP based access control.\n\nTo fix this security issue, the following changes have been made to all versions of Symfony2:\n\nA new Request::setTrustedProxies() method has been introduced and should be used intead of Request::trustProxyData() to enable the trust proxy mode. It takes an array of trusted proxy IP addresses as its argument:\n```\n// before (probably in your front controller script)\nRequest::trustProxyData();\n\n// after\nRequest::setTrustedProxies(array('1.1.1.1'));\n// 1.1.1.1 being the IP address of a trusted reverse proxy\n```\nThe Request::trustProxyData() method has been deprecated (when used, it automatically trusts the latest proxy in the chain -- which is the current remote address):\n```\nRequest::trustProxyData();\n\n// is equivalent to\nRequest::setTrustedProxies(array($request->server->get('REMOTE_ADDR')));\n```\nWe encourage all Symfony2 users to upgrade as soon as possible. It you don't want to upgrade to the latest version yet, you can also apply the following patches:\n\n- [Patch](https://github.com/symfony/symfony/compare/fc89d6b...9ce892c.patch) for Symfony 2.0.19\n- [Patch](https://github.com/symfony/symfony/compare/922c201...e5536f0.patch) for Symfony 2.1.4","published":"2024-05-30T00:34:48Z","modified":"2024-12-04T05:41:25.742334Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"symfony/http-foundation","fixedVersion":"2.0.19"},{"ecosystem":"Packagist","name":"symfony/http-foundation","fixedVersion":"2.1.4"},{"ecosystem":"Packagist","name":"symfony/symfony","fixedVersion":"2.0.19"},{"ecosystem":"Packagist","name":"symfony/symfony","fixedVersion":"2.1.4"}],"fix":{"url":"https://github.com/symfony/http-foundation/commit/5cde5229fc71a19cef2a0a933a18e08e43252f34","label":"symfony/http-foundation@5cde522"},"references":[{"type":"WEB","url":"https://github.com/symfony/http-foundation/commit/5cde5229fc71a19cef2a0a933a18e08e43252f34"},{"type":"WEB","url":"https://github.com/symfony/http-foundation/commit/795ac45c188ee2a729db4513e9dfd30b16a0ed35"},{"type":"WEB","url":"https://github.com/symfony/symfony/commit/9ce892cf4395e73b136e9b5cd1fae9e91995c93b"},{"type":"WEB","url":"https://github.com/symfony/symfony/commit/e5536f0fe10421da7ebbe0071343e94d039dfb97"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/http-foundation/2012-11-29.yaml"},{"type":"WEB","url":"https://symfony.com/blog/security-release-symfony-2-0-19-and-2-1-4"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-12-04T05:41:25.742334Z"}}