Back

MEDIUM

Exceptions displayed in non-debug configurations in Symfony

Published Mar 30, 2020

Description

In Symfony before versions 5.0.5 and 4.4.5, some properties of the Exception were not properly escaped when the `ErrorHandler` rendered it stacktrace. In addition, the stacktrace were displayed even in a non-debug configuration. The ErrorHandler now escape alls properties of the exception, and the stacktrace is only display in debug configuration. This issue is patched in symfony/http-foundation versions 4.4.5 and 5.0.5

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Mar 30, 2020
Updated Aug 4, 2024
Reserved Jan 2, 2020
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner GitHub_M
Published Mar 30, 2020
Updated Aug 4, 2024
Exploited since n/a
EUVD-2020-0350 GHSA-M884-279H-32V2