Commit 0f7667d
committed
security #cve-2018-14774 [HttpKernel] fix trusted headers management in HttpCache and InlineFragmentRenderer (nicolas-grekas)
* commit '725dee4cd8':
[HttpKernel] fix trusted headers management in HttpCache and InlineFragmentRenderer8 files changed
+350-92Lines changed: 350 additions & 92 deletions
File tree
Expand file treeCollapse file tree
Open diff view settings
Filter options
- src/Symfony/Component
- HttpFoundation
- HttpKernel
- Fragment
- HttpCache
- Tests
- Fragment
- HttpCache
Expand file treeCollapse file tree
Open diff view settings
Collapse file
src/Symfony/Component/HttpFoundation/Request.php
Copy file name to clipboardExpand all lines: src/Symfony/Component/HttpFoundation/Request.php+5Lines changed: 5 additions & 0 deletions
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| ||
1944 | 1944 | |
1945 | 1945 | |
1946 | 1946 | |
| 1947 | + |
| 1948 | + |
| 1949 | + |
| 1950 | + |
| 1951 | + |
1947 | 1952 | |
1948 | 1953 | |
1949 | 1954 | |
|
Collapse file
src/Symfony/Component/HttpKernel/Fragment/InlineFragmentRenderer.php
Copy file name to clipboardExpand all lines: src/Symfony/Component/HttpKernel/Fragment/InlineFragmentRenderer.php+2-27Lines changed: 2 additions & 27 deletions
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| ||
16 | 16 | |
17 | 17 | |
18 | 18 | |
| 19 | + |
19 | 20 | |
20 | 21 | |
21 | 22 | |
| ||
76 | 77 | |
77 | 78 | |
78 | 79 | |
79 | | - |
| 80 | + |
80 | 81 | |
81 | 82 | |
82 | 83 | |
| ||
109 | 110 | |
110 | 111 | |
111 | 112 | |
112 | | - |
113 | | - |
114 | | - |
115 | | - |
116 | | - |
117 | | - |
118 | | - |
119 | | - |
120 | | - |
121 | | - |
122 | | - |
123 | | - |
124 | | - |
125 | | - |
126 | | - |
127 | 113 | |
128 | 114 | |
129 | 115 | |
| ||
139 | 125 | |
140 | 126 | |
141 | 127 | |
142 | | - |
143 | | - |
144 | | - |
145 | | - |
146 | | - |
147 | | - |
148 | | - |
149 | | - |
150 | | - |
151 | | - |
152 | | - |
153 | 128 | |
154 | 129 | |
155 | 130 | |
|
Collapse file
src/Symfony/Component/HttpKernel/HttpCache/HttpCache.php
Copy file name to clipboardExpand all lines: src/Symfony/Component/HttpKernel/HttpCache/HttpCache.php+1-20Lines changed: 1 addition & 20 deletions
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| ||
468 | 468 | |
469 | 469 | |
470 | 470 | |
471 | | - |
472 | | - |
473 | | - |
474 | | - |
475 | | - |
476 | | - |
477 | | - |
478 | | - |
479 | | - |
480 | | - |
481 | | - |
482 | | - |
483 | | - |
484 | | - |
485 | | - |
486 | | - |
487 | | - |
488 | | - |
489 | 471 | |
490 | | - |
491 | | - |
| 472 | + |
492 | 473 | |
493 | 474 | |
494 | 475 | |
|
Collapse file
src/Symfony/Component/HttpKernel/HttpCache/SubRequestHandler.php
Copy file name to clipboard+100Lines changed: 100 additions & 0 deletions
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| ||
| 1 | + |
| 2 | + |
| 3 | + |
| 4 | + |
| 5 | + |
| 6 | + |
| 7 | + |
| 8 | + |
| 9 | + |
| 10 | + |
| 11 | + |
| 12 | + |
| 13 | + |
| 14 | + |
| 15 | + |
| 16 | + |
| 17 | + |
| 18 | + |
| 19 | + |
| 20 | + |
| 21 | + |
| 22 | + |
| 23 | + |
| 24 | + |
| 25 | + |
| 26 | + |
| 27 | + |
| 28 | + |
| 29 | + |
| 30 | + |
| 31 | + |
| 32 | + |
| 33 | + |
| 34 | + |
| 35 | + |
| 36 | + |
| 37 | + |
| 38 | + |
| 39 | + |
| 40 | + |
| 41 | + |
| 42 | + |
| 43 | + |
| 44 | + |
| 45 | + |
| 46 | + |
| 47 | + |
| 48 | + |
| 49 | + |
| 50 | + |
| 51 | + |
| 52 | + |
| 53 | + |
| 54 | + |
| 55 | + |
| 56 | + |
| 57 | + |
| 58 | + |
| 59 | + |
| 60 | + |
| 61 | + |
| 62 | + |
| 63 | + |
| 64 | + |
| 65 | + |
| 66 | + |
| 67 | + |
| 68 | + |
| 69 | + |
| 70 | + |
| 71 | + |
| 72 | + |
| 73 | + |
| 74 | + |
| 75 | + |
| 76 | + |
| 77 | + |
| 78 | + |
| 79 | + |
| 80 | + |
| 81 | + |
| 82 | + |
| 83 | + |
| 84 | + |
| 85 | + |
| 86 | + |
| 87 | + |
| 88 | + |
| 89 | + |
| 90 | + |
| 91 | + |
| 92 | + |
| 93 | + |
| 94 | + |
| 95 | + |
| 96 | + |
| 97 | + |
| 98 | + |
| 99 | + |
| 100 | + |
Collapse file
src/Symfony/Component/HttpKernel/Tests/Fragment/InlineFragmentRendererTest.php
Copy file name to clipboardExpand all lines: src/Symfony/Component/HttpKernel/Tests/Fragment/InlineFragmentRendererTest.php+20-18Lines changed: 20 additions & 18 deletions
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| ||
26 | 26 | |
27 | 27 | |
28 | 28 | |
29 | | - |
| 29 | + |
| 30 | + |
| 31 | + |
| 32 | + |
30 | 33 | |
31 | 34 | |
32 | 35 | |
33 | 36 | |
34 | | - |
| 37 | + |
| 38 | + |
35 | 39 | |
36 | 40 | |
37 | 41 | |
| ||
55 | 59 | |
56 | 60 | |
57 | 61 | |
58 | | - |
| 62 | + |
59 | 63 | |
60 | 64 | |
61 | 65 | |
| ||
83 | 87 | |
84 | 88 | |
85 | 89 | |
| 90 | + |
86 | 91 | |
87 | | - |
| 92 | + |
| 93 | + |
| 94 | + |
| 95 | + |
88 | 96 | |
89 | 97 | |
90 | 98 | |
| ||
168 | 176 | |
169 | 177 | |
170 | 178 | |
171 | | - |
172 | 179 | |
173 | 180 | |
174 | | - |
175 | 181 | |
| 182 | + |
176 | 183 | |
177 | 184 | |
178 | 185 | |
| ||
194 | 201 | |
195 | 202 | |
196 | 203 | |
197 | | - |
198 | | - |
199 | | - |
200 | | - |
| 204 | + |
| 205 | + |
201 | 206 | |
202 | 207 | |
203 | 208 | |
| ||
208 | 213 | |
209 | 214 | |
210 | 215 | |
211 | | - |
212 | | - |
213 | | - |
214 | | - |
215 | | - |
216 | | - |
| 216 | + |
| 217 | + |
| 218 | + |
217 | 219 | |
218 | 220 | |
219 | 221 | |
| ||
230 | 232 | |
231 | 233 | |
232 | 234 | |
233 | | - |
| 235 | + |
234 | 236 | |
235 | | - |
| 237 | + |
236 | 238 | |
237 | 239 | |
238 | 240 | |
|
Collapse file
src/Symfony/Component/HttpKernel/Tests/HttpCache/HttpCacheTest.php
Copy file name to clipboardExpand all lines: src/Symfony/Component/HttpKernel/Tests/HttpCache/HttpCacheTest.php+30-24Lines changed: 30 additions & 24 deletions
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| ||
1303 | 1303 | |
1304 | 1304 | |
1305 | 1305 | |
1306 | | - |
| 1306 | + |
| 1307 | + |
| 1308 | + |
| 1309 | + |
1307 | 1310 | |
1308 | 1311 | |
1309 | 1312 | |
1310 | 1313 | |
1311 | 1314 | |
1312 | | - |
| 1315 | + |
1313 | 1316 | |
1314 | 1317 | |
1315 | 1318 | |
1316 | 1319 | |
1317 | 1320 | |
| 1321 | + |
1318 | 1322 | |
1319 | | - |
| 1323 | + |
| 1324 | + |
| 1325 | + |
| 1326 | + |
| 1327 | + |
| 1328 | + |
1320 | 1329 | |
1321 | 1330 | |
1322 | 1331 | |
1323 | 1332 | |
1324 | 1333 | |
1325 | 1334 | |
1326 | 1335 | |
1327 | | - |
1328 | | - |
1329 | | - |
| 1336 | + |
| 1337 | + |
| 1338 | + |
1330 | 1339 | |
1331 | 1340 | |
1332 | 1341 | |
1333 | 1342 | |
1334 | | - |
| 1343 | + |
1335 | 1344 | |
1336 | | - |
| 1345 | + |
1337 | 1346 | |
1338 | 1347 | |
1339 | 1348 | |
1340 | | - |
1341 | | - |
| 1349 | + |
| 1350 | + |
| 1351 | + |
1342 | 1352 | |
1343 | 1353 | |
1344 | 1354 | |
1345 | | - |
| 1355 | + |
| 1356 | + |
| 1357 | + |
| 1358 | + |
| 1359 | + |
| 1360 | + |
1346 | 1361 | |
1347 | 1362 | |
1348 | | - |
| 1363 | + |
1349 | 1364 | |
1350 | 1365 | |
1351 | | - |
1352 | | - |
1353 | | - |
| 1366 | + |
| 1367 | + |
| 1368 | + |
1354 | 1369 | |
1355 | 1370 | |
1356 | 1371 | |
1357 | | - |
1358 | | - |
1359 | | - |
1360 | | - |
1361 | | - |
1362 | | - |
1363 | | - |
1364 | | - |
1365 | | - |
1366 | 1372 | |
1367 | 1373 | |
1368 | 1374 | |
|
0 commit comments