← Back to CVE List

CVE-2018-14774

Published: 2018-08-03T17:29Z
Last Modified: 2024-11-21T03:49Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
An issue was discovered in HttpKernel in Symfony 2.7.0 through 2.7.48, 2.8.0 through 2.8.43, 3.3.0 through 3.3.17, 3.4.0 through 3.4.13, 4.0.0 through 4.0.13, and 4.1.0 through 4.1.2. When using HttpCache, the values of the X-Forwarded-Host headers are implicitly set as trusted while this should be forbidden, leading to potential host header injection. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt