The Yaml::parse function in Symfony 2.0.x before 2.0.22 remote attackers to execute arbitrary PHP code via a PHP file, a different vulnerability than CVE-2013-1397.
Loading...
Loading...
The Yaml::parse function in Symfony 2.0.x before 2.0.22 remote attackers to execute arbitrary PHP code via a PHP file, a different vulnerability than CVE-2013-1397.
June 2, 2014
May 6, 2026
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| symfony/symfony | 2.0.4 ... v2.0.9 (17 versions) | 2.0.22 | — |
| symfony/yaml | 2.0.4 ... v2.0.9 (16 versions) | 2.0.22 | — |
Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.
See which npm, PyPI, Go, and Maven packages are affected by CVE-2013-1348
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.