Symfony 2.0.x before 2.0.20 does not process URL encoded data consistently within the Routing and Security components, which allows remote attackers to bypass intended URI restrictions via a doubly encoded string.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2012-12-27T11:00:00Z

Updated: 2024-09-17T00:46:20.194Z

Reserved: 2012-12-19T00:00:00Z

Link: CVE-2012-6431

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2012-12-27T11:47:01.790

Modified: 2013-01-07T05:00:00.000

Link: CVE-2012-6431

cve-icon Redhat

No data.