{"id":"GHSA-wwgf-3xp7-cxj4","aliases":[],"url":"https://o3.security/vulnerability/GHSA-wwgf-3xp7-cxj4","summary":"Potentially sensitive data exposure in Symfony Web Socket Bundle","details":"### Impact\nInside `Gos\\Bundle\\WebSocketBundle\\Server\\App\\Dispatcher\\TopicDispatcher::onPublish()`, messages are arbitrarily broadcasted to the related Topic if `Gos\\Bundle\\WebSocketBundle\\Server\\App\\Dispatcher\\TopicDispatcher::dispatch()` does not succeed.  The `dispatch()` method can be considered to not succeed if (depending on the version of the bundle) the callback defined on a topic route is misconfigured, a `Gos\\Bundle\\WebSocketBundle\\Topic\\TopicInterface` implementation is not found for the callback, a topic which also implements `Gos\\Bundle\\WebSocketBundle\\Topic\\SecuredTopicInterface` rejects the connection, or an Exception is unhandled.  This can result in an unintended broadcast to the websocket server potentially with data that should be considered sensitive.\n\n### Patches\nIn 1.10.4, 2.6.1, and 3.3.0, `Gos\\Bundle\\WebSocketBundle\\Server\\App\\Dispatcher\\TopicDispatcher::onPublish()` has been changed to no longer broadcast an event's data if `Gos\\Bundle\\WebSocketBundle\\Server\\App\\Dispatcher\\TopicDispatcher::dispatch()` fails.\n\n### Workarounds\nUpgrade to 1.10.4, 2.6.1, and 3.3.0\n\nNote, the 1.x branch is considered end of support as of July 1, 2020.\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Open an issue in [this repository](https://github.com/GeniusesOfSymfony/WebSocketBundle)","published":"2020-07-07T16:33:45Z","modified":"2024-12-02T05:44:47.757624Z","cvss":{"score":5.9,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"gos/web-socket-bundle","fixedVersion":"1.10.4"},{"ecosystem":"Packagist","name":"gos/web-socket-bundle","fixedVersion":"2.6.1"},{"ecosystem":"Packagist","name":"gos/web-socket-bundle","fixedVersion":"3.3.0"}],"fix":{"url":"https://github.com/FriendsOfPHP/security-advisories/commit/942fd37245cb724ba8cc8d6f11f075a1bd53b338","label":"FriendsOfPHP/security-advisories@942fd37"},"references":[{"type":"WEB","url":"https://github.com/GeniusesOfSymfony/WebSocketBundle/security/advisories/GHSA-wwgf-3xp7-cxj4"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/commit/942fd37245cb724ba8cc8d6f11f075a1bd53b338"},{"type":"PACKAGE","url":"https://github.com/GeniusesOfSymfony/WebSocketBundle"},{"type":"WEB","url":"https://snyk.io/vuln/SNYK-PHP-GOSWEBSOCKETBUNDLE-575401"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-12-02T05:44:47.757624Z"}}