CVE-2018-19790: Debian Linux

Medium severity, CVSS 6.1. EPSS: 1.5% chance of exploitation in the next 30 days.

An open redirect was discovered in Symfony 2.7.x before 2.7.50, 2.8.x before 2.8.49, 3.x before 3.4.20, 4.0.x before 4.0.15, 4.1.x before 4.1.9 and 4.2.x before 4.2.1. By using backslashes in the `_failure_path` input field of login forms, an attacker can work around the redirection target restrictions and effectively redirect the user to any domain after login.

Affected products

  • Debian Debian Linux: version 8.0 only
  • Fedoraproject Fedora: version 28 only
  • Sensiolabs Symfony: from 2.7.0, before 2.7.50 (fixed in 2.7.50); from 2.8.0, before 2.8.49 (fixed in 2.8.49); from 3.0.0, before 3.4.20 (fixed in 3.4.20); from 4.0.0, before 4.0.15 (fixed in 4.0.15); from 4.1.0, before 4.1.9 (fixed in 4.1.9); from 4.2.0, before 4.2.1 (fixed in 4.2.1)

Published 2018-12-18. Last modified 2026-06-17.