Description
Symfony 1 is a community-driven fork of the 1.x branch of Symfony, a PHP framework for web projects. Starting in version 1.1.0 and prior to version 1.5.19, Symfony 1 has a gadget chain due to dangerous deserialization in `sfNamespacedParameterHolder` class that would enable an attacker to get remote code execution if a developer deserializes user input in their project. Version 1.5.19 contains a patch for the issue.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-0981 | Symfony 1 is a community-driven fork of the 1.x branch of Symfony, a PHP framework for web projects. Starting in version 1.1.0 and prior to version 1.5.19, Symfony 1 has a gadget chain due to dangerous deserialization in `sfNamespacedParameterHolder` class that would enable an attacker to get remote code execution if a developer deserializes user input in their project. Version 1.5.19 contains a patch for the issue. |
Github GHSA |
GHSA-pv9j-c53q-h433 | Gadget chain in Symfony 1 due to uncontrolled unserialized input in sfNamespacedParameterHolder |
References
History
Fri, 05 Dec 2025 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Friendsofsymfony1
Friendsofsymfony1 symfony1 |
|
| CPEs | cpe:2.3:a:friendsofsymfony1:symfony1:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Friendsofsymfony1
Friendsofsymfony1 symfony1 |
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-20T20:33:11.104Z
Reserved: 2024-03-11T22:45:07.686Z
Link: CVE-2024-28861
Updated: 2024-08-02T00:56:58.132Z
Status : Analyzed
Published: 2024-03-22T17:15:07.770
Modified: 2025-12-05T19:59:09.477
Link: CVE-2024-28861
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA