CVE-2012-6431: Sensiolabs Symfony

Medium severity, CVSS 6.4. EPSS: 1.9% chance of exploitation in the next 30 days.

Symfony 2.0.x before 2.0.20 does not process URL encoded data consistently within the Routing and Security components, which allows remote attackers to bypass intended URI restrictions via a doubly encoded string.

Affected products

  • Sensiolabs Symfony: version 2.0.0 only; version 2.0.1 only; version 2.0.2 only; version 2.0.3 only; version 2.0.4 only; version 2.0.5 only; …

Published 2012-12-27. Last modified 2026-06-16.