symfony/security Security Advisories (17)
-
[MEDIUM] CVE-2021-21424: Prevent user enumeration via response content in authentication mechanisms
PKSA-8ws6-qn2n-55bs CVE-2021-21424 GHSA-5pv8-ppvj-4h68
Affected version: >=2.8.0,<3.0.0|>=3.0.0,<3.1.0|>=3.1.0,<3.2.0|>=3.2.0,<3.3.0|>=3.3.0,<3.4.0|>=3.4.0,<3.4.49|>=4.0.0,<4.1.0|>=4.1.0,<4.2.0|>=4.2.0,<4.3.0|>=4.3.0,<4.4.0|>=4.4.0,<4.4.24
Reported by:
GitHub, FriendsOfPHP/security-advisories -
[HIGH] CVE-2020-5275: All rules set in "access_control" are required when the firewall is configured with the unanimous strategy
PKSA-dtfj-z29g-v2fb CVE-2020-5275 GHSA-g4m9-5hpf-hx72
Affected version: >=4.4.0,<4.4.7
Reported by:
GitHub, FriendsOfPHP/security-advisories -
[HIGH] CVE-2019-10911: Add a separator in the remember me cookie hash
PKSA-cf8d-qjyv-5mqt CVE-2019-10911 GHSA-cchx-mfrc-fwqr
Affected version: >=2.7.0,<2.7.51|>=2.8.0,<2.8.50|>=3.0.0,<3.1.0|>=3.1.0,<3.2.0|>=3.2.0,<3.3.0|>=3.3.0,<3.4.0|>=3.4.0,<3.4.26|>=4.0.0,<4.1.0|>=4.1.0,<4.1.12|>=4.2.0,<4.2.7
Reported by:
GitHub, FriendsOfPHP/security-advisories -
[MEDIUM] CVE-2018-19790: Open Redirect Vulnerability on login
PKSA-f5hy-hfjt-gmst CVE-2018-19790 GHSA-89r2-5g34-2g47
Affected version: >=2.7.38,<2.7.50|>=2.8.0,<2.8.49|>=3.0.0,<3.1.0|>=3.1.0,<3.2.0|>=3.2.0,<3.3.0|>=3.3.0,<3.4.0|>=3.4.0,<3.4.19|>=4.0.0,<4.0.15|>=4.1.0,<4.1.9|>=4.2.0,<4.2.1
Reported by:
GitHub, FriendsOfPHP/security-advisories -
[CRITICAL] CVE-2018-11407: Unauthorized access on a misconfigured LDAP server when using an empty password
PKSA-hdr7-z345-3h59 CVE-2018-11407 GHSA-35c5-28pg-2qg4
Affected version: >=2.8.0,<2.8.37|>=3.0.0,<3.1.0|>=3.1.0,<3.2.0|>=3.2.0,<3.3.0|>=3.3.0,<3.3.17|>=3.4.0,<3.4.7|>=4.0.0,<4.0.7
Reported by:
GitHub, FriendsOfPHP/security-advisories -
[HIGH] CVE-2018-11406: CSRF Token Fixation
PKSA-3grm-n326-q5z3 CVE-2018-11406 GHSA-g4g7-q726-v5hg
Affected version: >=2.0.0,<2.1.0|>=2.1.0,<2.2.0|>=2.2.0,<2.3.0|>=2.3.0,<2.4.0|>=2.4.0,<2.5.0|>=2.5.0,<2.6.0|>=2.6.0,<2.7.0|>=2.7.0,<2.7.48|>=2.8.0,<2.8.41|>=3.0.0,<3.1.0|>=3.1.0,<3.2.0|>=3.2.0,<3.3.0|>=3.3.0,<3.3.17|>=3.4.0,<3.4.11|>=4.0.0,<4.0.11
Reported by:
GitHub, FriendsOfPHP/security-advisories -
[HIGH] CVE-2018-11385: Session Fixation Issue for Guard Authentication
PKSA-zk3t-cmdy-sy2k CVE-2018-11385 GHSA-g4rg-rw65-8hfg
Affected version: >=2.0.0,<2.1.0|>=2.1.0,<2.2.0|>=2.2.0,<2.3.0|>=2.3.0,<2.4.0|>=2.4.0,<2.5.0|>=2.5.0,<2.6.0|>=2.6.0,<2.7.0|>=2.7.0,<2.7.48|>=2.8.0,<2.8.41|>=3.0.0,<3.1.0|>=3.1.0,<3.2.0|>=3.2.0,<3.3.0|>=3.3.0,<3.3.17|>=3.4.0,<3.4.11|>=4.0.0,<4.0.11
Reported by:
GitHub, FriendsOfPHP/security-advisories -
[MEDIUM] CVE-2017-16652: Open redirect vulnerability on security handlers
PKSA-wnnc-tg88-zcy1 CVE-2017-16652 GHSA-r7p7-qr7p-2rrf
Affected version: >=2.7.0,<2.7.38|>=2.8.0,<2.8.31|>=3.0.0,<3.1.0|>=3.1.0,<3.2.0|>=3.2.0,<3.2.14|>=3.3.0,<3.3.13
Reported by:
GitHub, FriendsOfPHP/security-advisories -
[MEDIUM] CVE-2017-16653: CSRF protection does not use different tokens for HTTP and HTTPS
PKSA-ctvc-mfjq-9myr CVE-2017-16653 GHSA-92x6-h2gr-8gxq
Affected version: >=2.7.0,<2.7.38|>=2.8.0,<2.8.31|>=3.0.0,<3.1.0|>=3.1.0,<3.2.0|>=3.2.0,<3.2.14|>=3.3.0,<3.3.13
Reported by:
GitHub, FriendsOfPHP/security-advisories -
[CRITICAL] CVE-2017-11365: Empty passwords validation issue
PKSA-yw14-x65g-6hbm CVE-2017-11365 GHSA-q87v-q8fw-gmj5
Affected version: >=2.7.30,<2.7.32|>=2.8.23,<2.8.25|>=3.2.10,<3.2.12|>=3.3.3,<3.3.5
Reported by:
GitHub, FriendsOfPHP/security-advisories -
[CRITICAL] CVE-2016-2403: Unauthorized access on a misconfigured Ldap server when using an empty password
PKSA-sp82-1f23-y66c CVE-2016-2403 GHSA-wvj5-r78r-hhfq
Affected version: >=2.8.0,<2.8.6|>=3.0.0,<3.0.6
Reported by:
GitHub, FriendsOfPHP/security-advisories -
[HIGH] CVE-2016-4423: Large username storage in session
PKSA-9t3p-7s5c-ydgx CVE-2016-4423 GHSA-whgv-8cg3-7hcm
Affected version: >=2.3.0,<2.3.41|>=2.4.0,<2.5.0|>=2.5.0,<2.6.0|>=2.6.0,<2.7.0|>=2.7.0,<2.7.13|>=2.8.0,<2.8.6|>=3.0.0,<3.0.6
Reported by:
GitHub, FriendsOfPHP/security-advisories -
[HIGH] CVE-2016-1902: SecureRandom's fallback not secure when OpenSSL fails
PKSA-c8q4-qf8b-nmtq CVE-2016-1902 GHSA-jjx5-fq5g-8xpc
Affected version: >=2.3.0,<2.3.37|>=2.4.0,<2.5.0|>=2.5.0,<2.6.0|>=2.6.0,<2.6.13|>=2.7.0,<2.7.9
Reported by:
GitHub, FriendsOfPHP/security-advisories -
[HIGH] CVE-2015-8125: Potential Remote Timing Attack Vulnerability in Security Remember-Me Service
PKSA-krbp-gnkk-54bj CVE-2015-8125 GHSA-g97c-jfx6-xvxh
Affected version: >=2.3.0,<2.3.35|>=2.4.0,<2.5.0|>=2.5.0,<2.6.0|>=2.6.0,<2.6.12|>=2.7.0,<2.7.7
Reported by:
GitHub, FriendsOfPHP/security-advisories -
[LOW] CVE-2015-8124: Session Fixation in the "Remember Me" Login Feature
PKSA-3bc7-m4n7-t49v CVE-2015-8124 GHSA-j5jh-hpr4-h332
Affected version: >=2.3.0,<2.3.35|>=2.4.0,<2.5.0|>=2.5.0,<2.6.0|>=2.6.0,<2.6.12|>=2.7.0,<2.7.7
Reported by:
GitHub, FriendsOfPHP/security-advisories -
[MEDIUM] Possible DOS attack with long user-submitted passwords
PKSA-9qgs-5jdb-1mfq CVE-2013-5958 GHSA-cr49-fx2v-9p57
Affected version: >=2.0.0,<2.0.25|>=2.1.0,<2.1.13|>=2.2.0,<2.2.9|>=2.3.0,<2.3.6
Reported by:
GitHub, FriendsOfPHP/security-advisories -
[MEDIUM] Routes behind a firewall are accessible even when not logged in
PKSA-468d-qs45-4h29 CVE-2012-6431 GHSA-83c3-qx27-2rwr
Affected version: >=2.0.0,<2.0.19
Reported by:
GitHub, FriendsOfPHP/security-advisories