Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-45074

Gravedad CVSS v4.0:
ALTA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
14/07/2026
Última modificación:
15/07/2026

Descripción

*** Pendiente de traducción *** Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 7.1.0 until 7.4.12 and 8.0.12, Cas2Handler builds the CAS service parameter from Request::getSchemeAndHttpHost(), which reflects an attacker-controlled Host header when framework.trusted_hosts is not configured; an attacker controlling another application registered with the same CAS server can replay a victim ticket against the Symfony application and authenticate as the victim. This issue is fixed in versions 7.4.12 and 8.0.12.

Productos y versiones vulnerables

CPE Desde Hasta
cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:* 7.1.0 (incluyendo) 7.4.12 (excluyendo)
cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:* 8.0.0 (incluyendo) 8.0.12 (excluyendo)