Security Advisory

CVE-2019-10910

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2019-05-16 21:31:41
Last updated 2024-08-04 22:40:15
Assigner mitre
State PUBLISHED

Description

In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, when service ids allow user input, this could allow for SQL Injection and remote code execution. This is related to symfony/dependency-injection.