An issue was discovered in Symfony 2.8.0 through 2.8.50, 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4.3.7. If an application passes unvalidated user input as the file for which MIME type validation should occur, then arbitrary arguments are passed to the underlying file command. This is related to symfony/http-foundation (and symfony/mime in 4.3.x).
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2019-11-21T22:19:52

Updated: 2019-11-22T02:07:11

Reserved: 2019-11-12T00:00:00


Link: CVE-2019-18888

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2019-11-21T23:15:13.530

Modified: 2023-11-07T03:07:18.503


Link: CVE-2019-18888

JSON object: View

cve-icon Redhat Information

No data.

CWE