Learn about CVE-2021-41267, a vulnerability in Symfony 5.2 allowing attackers to exploit the `X-Forwarded-Prefix` header, potentially leading to web cache poisoning. Find out the impact, affected systems, and mitigation steps.
Symfony/Http-Kernel is the HTTP kernel component for Symfony, a PHP framework. A vulnerability in Symfony 5.2 allows attackers to exploit the
X-Forwarded-Prefix
header, potentially leading to web cache poisoning.
Understanding CVE-2021-41267
What is CVE-2021-41267?
Symfony 5.2 vulnerability allows a forged
X-Forwarded-Prefix
header, enabling attackers to conduct web cache poisoning.
The Impact of CVE-2021-41267
The vulnerability poses a medium severity risk with a CVSS base score of 6.5. Attackers could manipulate requests, leading to cache poisoning.
Technical Details of CVE-2021-41267
Vulnerability Description
X-Forwarded-Prefix
headerAffected Systems and Versions
Exploitation Mechanism
Mitigation and Prevention
Immediate Steps to Take
X-Forwarded-Prefix
headerLong-Term Security Practices
Patching and Updates