symfony/http-kernel Security Advisories (7)
-
[MEDIUM] CVE-2022-24894: Prevent storing cookie headers in HttpCache
PKSA-hr4y-jwk2-1yb9 CVE-2022-24894 GHSA-h7vf-5wrv-9fhv
Affected version: >=2.0.0,<2.1.0|>=2.1.0,<2.2.0|>=2.2.0,<2.3.0|>=2.3.0,<2.4.0|>=2.4.0,<2.5.0|>=2.5.0,<2.6.0|>=2.6.0,<2.7.0|>=2.7.0,<2.8.0|>=2.8.0,<3.0.0|>=3.0.0,<3.1.0|>=3.1.0,<3.2.0|>=3.2.0,<3.3.0|>=3.3.0,<3.4.0|>=3.4.0,<4.0.0|>=4.0.0,<4.1.0|>=4.1.0,<4.2.0|>=4.2.0,<4.3.0|>=4.3.0,<4.4.0|>=4.4.0,<4.4.50|>=5.0.0,<5.1.0|>=5.1.0,<5.2.0|>=5.2.0,<5.3.0|>=5.3.0,<5.4.0|>=5.4.0,<5.4.20|>=6.0.0,<6.0.20|>=6.1.0,<6.1.12|>=6.2.0,<6.2.6
Reported by:
GitHub, FriendsOfPHP/security-advisories -
[MEDIUM] CVE-2021-41267: Webcache Poisoning via X-Forwarded-Prefix and sub-request
PKSA-ftqt-8gzv-r53t CVE-2021-41267 GHSA-q3j3-w37x-hq2q
Affected version: >=5.2.0,<5.3.0|>=5.3.0,<5.3.12
Reported by:
GitHub, FriendsOfPHP/security-advisories -
[HIGH] CVE-2020-15094: Prevent RCE when calling untrusted remote with CachingHttpClient
PKSA-8knv-7jsn-12w8 CVE-2020-15094 GHSA-754h-5r27-7x3r
Affected version: >=4.3.0,<4.4.0|>=4.4.0,<4.4.13|>=5.0.0,<5.1.0|>=5.1.0,<5.1.5
Reported by:
GitHub, FriendsOfPHP/security-advisories -
[HIGH] CVE-2019-18887: Use constant time comparison in UriSigner
PKSA-sn9k-4yr8-6s9c CVE-2019-18887 GHSA-q8hg-pf8v-cxrv
Affected version: >=2.2.0,<2.3.0|>=2.3.0,<2.4.0|>=2.4.0,<2.5.0|>=2.5.0,<2.6.0|>=2.6.0,<2.7.0|>=2.7.0,<2.8.0|>=2.8.0,<2.8.52|>=3.0.0,<3.1.0|>=3.1.0,<3.2.0|>=3.2.0,<3.3.0|>=3.3.0,<3.4.0|>=3.4.0,<3.4.35|>=4.0.0,<4.1.0|>=4.1.0,<4.2.0|>=4.2.0,<4.2.12|>=4.3.0,<4.3.8
Reported by:
GitHub, FriendsOfPHP/security-advisories -
[MEDIUM] CVE-2015-4050: ESI unauthorized access
PKSA-35ts-w5by-rx5d CVE-2015-4050 GHSA-qmqw-mpqp-mr54
Affected version: >=2.3.19,<2.3.29|>=2.4.9,<2.5.0|>=2.5.4,<2.5.12|>=2.6.0,<2.6.8
Reported by:
GitHub, FriendsOfPHP/security-advisories -
[MEDIUM] Esi Code Injection
PKSA-15jn-wzq4-94pw CVE-2015-2308 GHSA-5c58-w9xc-qcj9
Affected version: >=2.0.0,<2.1.0|>=2.1.0,<2.2.0|>=2.2.0,<2.3.0|>=2.3.0,<2.3.27|>=2.4.0,<2.5.0|>=2.5.0,<2.5.11|>=2.6.0,<2.6.6
Reported by:
GitHub, FriendsOfPHP/security-advisories -
[HIGH] Direct access of ESI URLs behind a trusted proxy
PKSA-6dsk-crym-v443 CVE-2014-5245 GHSA-wvjv-p5rr-mmqm
Affected version: >=2.0.0,<2.1.0|>=2.1.0,<2.2.0|>=2.2.0,<2.3.0|>=2.3.0,<2.3.19|>=2.4.0,<2.4.9|>=2.5.0,<2.5.4
Reported by:
GitHub, FriendsOfPHP/security-advisories