CVE-2020-5255CWE-435

Prevent cache poisoning via a Response Content-Type header

Low · published March 30, 2020

CVSS v3.1
2.6
EPSS
1%
Percentile
68.5
In the wild
Unconfirmed
What it is

In Symfony before versions 4.4.7 and 5.0.7, when a `Response` does not contain a `Content-Type` header, affected versions of Symfony can fallback to the format defined in the `Accept` header of the request, leading to a possible mismatch between the response's content and `Content-Type` header. When the response is cached, this can prevent the use of the website by other users. This has been patched in versions 4.4.7 and 5.0.7.

The record
Technical detail
CVSS v3.1
2.6 · LOW
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:N/A:L
CVSS v4.0
Not supplied
EPSS
0.01297 · 68.5th percentile
Weakness
CWE-435 · Improper Interaction Between Multiple Correctly-Behaving Entities
Published
2020-03-30T19:30Z
EPSS history
Timeline
  • 30 MAR 19:30Z
    Prevent cache poisoning via a Response Content-Type header
    cvelistv5