CVE-2020-5255

CVE-2020-5255

In Symfony before version 4.4, when a `Response` does not contain a `Content-Type` header, affected versions of Symfony can fallback to the format defined in the `Accept` header of the request, leading to a possible mismatch between the response's content and `Content-Type` header. When the response is cached, this can prevent the use of the website by other users. This has been patched in version 4.4.

Source: CVE-2020-5255

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다