symfony/symfony Security Advisories for v3.4.6 (24)
- 
                        [HIGH] CVE-2024-51736: Command execution hijack on Windows with Process classPKSA-jdmc-h4p3-hds2 CVE-2024-51736 GHSA-qq5c-677p-737q Affected version: >=2.0.0,<3.0.0|>=3.0.0,<4.0.0|>=4.0.0,<5.0.0|>=5.0.0,<5.1.0|>=5.1.0,<5.2.0|>=5.2.0,<5.3.0|>=5.3.0,<5.4.0|>=5.4.0,<5.4.46|>=6.0.0,<6.1.0|>=6.1.0,<6.2.0|>=6.2.0,<6.3.0|>=6.3.0,<6.4.0|>=6.4.0,<6.4.14|>=7.0.0,<7.1.0|>=7.1.0,<7.1.7 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [LOW] CVE-2024-50345: Open redirect via browser-sanitized URLsPKSA-rb2q-qy38-2dj7 CVE-2024-50345 GHSA-mrqx-rp3w-jpjp Affected version: >=2.0.0,<3.0.0|>=3.0.0,<4.0.0|>=4.0.0,<5.0.0|>=5.0.0,<5.1.0|>=5.1.0,<5.2.0|>=5.2.0,<5.3.0|>=5.3.0,<5.4.0|>=5.4.0,<5.4.46|>=6.0.0,<6.1.0|>=6.1.0,<6.2.0|>=6.2.0,<6.3.0|>=6.3.0,<6.4.0|>=6.4.0,<6.4.14|>=7.0.0,<7.1.0|>=7.1.0,<7.1.7 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [LOW] CVE-2024-50343: Incorrect response from Validator when input ends with ` `PKSA-19z7-hn1j-mtcg CVE-2024-50343 GHSA-g3rh-rrhp-jhh9 Affected version: >=2.0.0,<3.0.0|>=3.0.0,<4.0.0|>=4.0.0,<5.0.0|>=5.0.0,<5.1.0|>=5.1.0,<5.2.0|>=5.2.0,<5.3.0|>=5.3.0,<5.4.0|>=5.4.0,<5.4.43|>=6.0.0,<6.1.0|>=6.1.0,<6.2.0|>=6.2.0,<6.3.0|>=6.3.0,<6.4.0|>=6.4.0,<6.4.11|>=7.0.0,<7.1.0|>=7.1.0,<7.1.4 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [MEDIUM] CVE-2023-46734: Potential XSS vulnerabilities in CodeExtension filtersPKSA-y38q-cfj7-gm5p CVE-2023-46734 GHSA-q847-2q57-wmr3 Affected version: >=2.0.0,<2.1.0|>=2.1.0,<2.2.0|>=2.2.0,<2.3.0|>=2.3.0,<2.4.0|>=2.4.0,<2.5.0|>=2.5.0,<2.6.0|>=2.6.0,<2.7.0|>=2.7.0,<2.8.0|>=2.8.0,<3.0.0|>=3.0.0,<3.1.0|>=3.1.0,<3.2.0|>=3.2.0,<3.3.0|>=3.3.0,<3.4.0|>=3.4.0,<4.0.0|>=4.0.0,<4.1.0|>=4.1.0,<4.2.0|>=4.2.0,<4.3.0|>=4.3.0,<4.4.0|>=4.4.0,<4.4.51|>=5.0.0,<5.1.0|>=5.1.0,<5.2.0|>=5.2.0,<5.3.0|>=5.3.0,<5.4.0|>=5.4.0,<5.4.31|>=6.0.0,<6.1.0|>=6.1.0,<6.2.0|>=6.2.0,<6.3.0|>=6.3.0,<6.3.8 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [MEDIUM] CVE-2022-24895: Possible CSRF token fixationPKSA-53qn-v9cx-yn6c CVE-2022-24895 GHSA-3gv2-29qc-v67m Affected version: >=2.0.0,<2.1.0|>=2.1.0,<2.2.0|>=2.2.0,<2.3.0|>=2.3.0,<2.4.0|>=2.4.0,<2.5.0|>=2.5.0,<2.6.0|>=2.6.0,<2.7.0|>=2.7.0,<2.8.0|>=2.8.0,<3.0.0|>=3.0.0,<3.1.0|>=3.1.0,<3.2.0|>=3.2.0,<3.3.0|>=3.3.0,<3.4.0|>=3.4.0,<4.0.0|>=4.0.0,<4.1.0|>=4.1.0,<4.2.0|>=4.2.0,<4.3.0|>=4.3.0,<4.4.0|>=4.4.0,<4.4.50|>=5.0.0,<5.1.0|>=5.1.0,<5.2.0|>=5.2.0,<5.3.0|>=5.3.0,<5.4.0|>=5.4.0,<5.4.20|>=6.0.0,<6.0.20|>=6.1.0,<6.1.12|>=6.2.0,<6.2.6 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [MEDIUM] CVE-2022-24894: Prevent storing cookie headers in HttpCachePKSA-x3kp-hpzz-4th3 CVE-2022-24894 GHSA-h7vf-5wrv-9fhv Affected version: >=2.0.0,<2.1.0|>=2.1.0,<2.2.0|>=2.2.0,<2.3.0|>=2.3.0,<2.4.0|>=2.4.0,<2.5.0|>=2.5.0,<2.6.0|>=2.6.0,<2.7.0|>=2.7.0,<2.8.0|>=2.8.0,<3.0.0|>=3.0.0,<3.1.0|>=3.1.0,<3.2.0|>=3.2.0,<3.3.0|>=3.3.0,<3.4.0|>=3.4.0,<4.0.0|>=4.0.0,<4.1.0|>=4.1.0,<4.2.0|>=4.2.0,<4.3.0|>=4.3.0,<4.4.0|>=4.4.0,<4.4.50|>=5.0.0,<5.1.0|>=5.1.0,<5.2.0|>=5.2.0,<5.3.0|>=5.3.0,<5.4.0|>=5.4.0,<5.4.20|>=6.0.0,<6.0.20|>=6.1.0,<6.1.12|>=6.2.0,<6.2.6 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [HIGH] Symfony Host Header InjectionPKSA-6jwc-s2ck-4fyz CVE-2018-14774 GHSA-66p6-7p29-55p9 Affected version: >=4.1.0,<=4.1.2|>=4.0.0,<=4.0.13|>=3.4.0,<=3.4.13|>=3.3.0,<=3.3.17|>=2.8.0,<=2.8.43|>=2.7.0,<=2.7.48 Reported by: 
 GitHub
- 
                        [MEDIUM] CVE-2021-21424: Prevent user enumeration via response content in authentication mechanismsPKSA-hq66-h9fz-xgjz CVE-2021-21424 GHSA-5pv8-ppvj-4h68 Affected version: >=2.8.0,<3.0.0|>=3.0.0,<3.1.0|>=3.1.0,<3.2.0|>=3.2.0,<3.3.0|>=3.3.0,<3.4.0|>=3.4.0,<3.4.49|>=4.0.0,<4.1.0|>=4.1.0,<4.2.0|>=4.2.0,<4.3.0|>=4.3.0,<4.4.0|>=4.4.0,<4.4.24|>=5.0.0,<5.1.0|>=5.1.0,<5.2.0|>=5.2.0,<5.2.9 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [HIGH] CVE-2019-18888: Prevent argument injection in a MimeTypeGuesserPKSA-7c17-cdm2-nd4n CVE-2019-18888 GHSA-xhh6-956q-4q69 Affected version: >=2.0.0,<2.1.0|>=2.1.0,<2.2.0|>=2.2.0,<2.3.0|>=2.3.0,<2.4.0|>=2.4.0,<2.5.0|>=2.5.0,<2.6.0|>=2.6.0,<2.7.0|>=2.7.0,<2.8.0|>=2.8.0,<2.8.52|>=3.0.0,<3.1.0|>=3.1.0,<3.2.0|>=3.2.0,<3.3.0|>=3.3.0,<3.4.0|>=3.4.0,<3.4.35|>=4.0.0,<4.1.0|>=4.1.0,<4.2.0|>=4.2.0,<4.2.12|>=4.3.0,<4.3.8 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [HIGH] CVE-2019-18887: Use constant time comparison in UriSignerPKSA-2c18-zmpb-j18r CVE-2019-18887 GHSA-q8hg-pf8v-cxrv Affected version: >=2.2.0,<2.3.0|>=2.3.0,<2.4.0|>=2.4.0,<2.5.0|>=2.5.0,<2.6.0|>=2.6.0,<2.7.0|>=2.7.0,<2.8.0|>=2.8.0,<2.8.52|>=3.0.0,<3.1.0|>=3.1.0,<3.2.0|>=3.2.0,<3.3.0|>=3.3.0,<3.4.0|>=3.4.0,<3.4.35|>=4.0.0,<4.1.0|>=4.1.0,<4.2.0|>=4.2.0,<4.2.12|>=4.3.0,<4.3.8 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [CRITICAL] CVE-2019-18889: Forbid serializing AbstractAdapter and TagAwareAdapter instancesPKSA-466j-t9tp-6p9g CVE-2019-18889 GHSA-79gr-58r3-pwm3 Affected version: >=3.1.0,<3.2.0|>=3.2.0,<3.3.0|>=3.3.0,<3.4.0|>=3.4.0,<3.4.35|>=4.0.0,<4.1.0|>=4.1.0,<4.2.0|>=4.2.0,<4.2.12|>=4.3.0,<4.3.8 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [CRITICAL] CVE-2019-10910: Check service IDs are validPKSA-wzwb-pd6v-vngj CVE-2019-10910 GHSA-pgwj-prpq-jpc2 Affected version: >=2.7.0,<2.7.51|>=2.8.0,<2.8.50|>=3.0.0,<3.1.0|>=3.1.0,<3.2.0|>=3.2.0,<3.3.0|>=3.3.0,<3.4.0|>=3.4.0,<3.4.26|>=4.0.0,<4.1.0|>=4.1.0,<4.1.12|>=4.2.0,<4.2.7 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [MEDIUM] CVE-2019-10909: Escape validation messages in the PHP templating enginePKSA-m1rn-sznw-gwbr CVE-2019-10909 GHSA-g996-q5r8-w7g2 Affected version: >=2.7.0,<2.7.51|>=2.8.0,<2.8.50|>=3.0.0,<3.1.0|>=3.1.0,<3.2.0|>=3.2.0,<3.3.0|>=3.3.0,<3.4.0|>=3.4.0,<3.4.26|>=4.0.0,<4.1.0|>=4.1.0,<4.1.12|>=4.2.0,<4.2.7 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [HIGH] CVE-2019-10912: Prevent destructors with side-effects from being unserializedPKSA-mh8w-p7pd-ryq7 CVE-2019-10912 GHSA-w2fr-65vp-mxw3 Affected version: >=2.8.0,<2.8.50|>=3.0.0,<3.1.0|>=3.1.0,<3.2.0|>=3.2.0,<3.3.0|>=3.3.0,<3.4.0|>=3.4.0,<3.4.26|>=4.0.0,<4.1.0|>=4.1.0,<4.1.12|>=4.2.0,<4.2.7 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [HIGH] CVE-2019-10911: Add a separator in the remember me cookie hashPKSA-6kxq-3xc4-hmkm CVE-2019-10911 GHSA-cchx-mfrc-fwqr Affected version: >=2.7.0,<2.7.51|>=2.8.0,<2.8.50|>=3.0.0,<3.1.0|>=3.1.0,<3.2.0|>=3.2.0,<3.3.0|>=3.3.0,<3.4.0|>=3.4.0,<3.4.26|>=4.0.0,<4.1.0|>=4.1.0,<4.1.12|>=4.2.0,<4.2.7 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [CRITICAL] CVE-2019-10913: Reject invalid HTTP method overridesPKSA-knvs-fy6n-bhp7 CVE-2019-10913 GHSA-x92h-wmg2-6hp7 Affected version: >=2.7.0,<2.7.51|>=2.8.0,<2.8.50|>=3.0.0,<3.1.0|>=3.1.0,<3.2.0|>=3.2.0,<3.3.0|>=3.3.0,<3.4.0|>=3.4.0,<3.4.26|>=4.0.0,<4.1.0|>=4.1.0,<4.1.12|>=4.2.0,<4.2.7 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [MEDIUM] CVE-2018-19790: Open Redirect Vulnerability on loginPKSA-zd86-wd6f-tb9n CVE-2018-19790 GHSA-89r2-5g34-2g47 Affected version: >=2.7.38,<2.7.50|>=2.8.0,<2.8.49|>=3.0.0,<3.1.0|>=3.1.0,<3.2.0|>=3.2.0,<3.3.0|>=3.3.0,<3.4.0|>=3.4.0,<3.4.20|>=4.0.0,<4.0.15|>=4.1.0,<4.1.9|>=4.2.0,<4.2.1 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [MEDIUM] CVE-2018-19789: Temporary uploaded file path disclosurePKSA-zc56-fpqy-7zct CVE-2018-19789 GHSA-x3cf-w64x-4cp2 Affected version: >=2.7.38,<2.7.50|>=2.8.0,<2.8.49|>=3.0.0,<3.1.0|>=3.1.0,<3.2.0|>=3.2.0,<3.3.0|>=3.3.0,<3.4.0|>=3.4.0,<3.4.20|>=4.0.0,<4.0.15|>=4.1.0,<4.1.9|>=4.2.0,<4.2.1 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [MEDIUM] CVE-2018-14773: Remove support for legacy and risky HTTP headersPKSA-vh39-74ft-ywr6 CVE-2018-14773 GHSA-8wgj-6wx8-h5hq Affected version: >=2.0.0,<2.1.0|>=2.1.0,<2.2.0|>=2.2.0,<2.3.0|>=2.3.0,<2.4.0|>=2.4.0,<2.5.0|>=2.5.0,<2.6.0|>=2.6.0,<2.7.0|>=2.7.0,<2.7.49|>=2.8.0,<2.8.44|>=3.0.0,<3.1.0|>=3.1.0,<3.2.0|>=3.2.0,<3.3.0|>=3.3.0,<3.3.18|>=3.4.0,<3.4.14|>=4.0.0,<4.0.14|>=4.1.0,<4.1.3 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [CRITICAL] CVE-2018-11407: Unauthorized access on a misconfigured LDAP server when using an empty passwordPKSA-sdqz-ygpm-k46x CVE-2018-11407 GHSA-35c5-28pg-2qg4 Affected version: >=2.8.0,<2.8.37|>=3.0.0,<3.1.0|>=3.1.0,<3.2.0|>=3.2.0,<3.3.0|>=3.3.0,<3.3.17|>=3.4.0,<3.4.7|>=4.0.0,<4.0.7 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [MEDIUM] CVE-2018-11408: Open redirect vulnerability on security handlersPKSA-pm7f-56fm-h5jv CVE-2018-11408 GHSA-7hwc-2cq4-6x2w Affected version: >=2.7.38,<2.7.48|>=2.8.0,<2.8.41|>=3.0.0,<3.1.0|>=3.1.0,<3.2.0|>=3.2.0,<3.3.0|>=3.3.0,<3.3.17|>=3.4.0,<3.4.11|>=4.0.0,<4.0.11 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [HIGH] CVE-2018-11406: CSRF Token FixationPKSA-f442-tkzt-592s CVE-2018-11406 GHSA-g4g7-q726-v5hg Affected version: >=2.0.0,<2.1.0|>=2.1.0,<2.2.0|>=2.2.0,<2.3.0|>=2.3.0,<2.4.0|>=2.4.0,<2.5.0|>=2.5.0,<2.6.0|>=2.6.0,<2.7.0|>=2.7.0,<2.7.48|>=2.8.0,<2.8.41|>=3.0.0,<3.1.0|>=3.1.0,<3.2.0|>=3.2.0,<3.3.0|>=3.3.0,<3.3.17|>=3.4.0,<3.4.11|>=4.0.0,<4.0.11 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [MEDIUM] CVE-2018-11386: Denial of service when using PDOSessionHandlerPKSA-pzzd-51qv-shqy CVE-2018-11386 GHSA-r2rq-3h56-fqm4 Affected version: >=2.0.0,<2.1.0|>=2.1.0,<2.2.0|>=2.2.0,<2.3.0|>=2.3.0,<2.4.0|>=2.4.0,<2.5.0|>=2.5.0,<2.6.0|>=2.6.0,<2.7.0|>=2.7.0,<2.7.48|>=2.8.0,<2.8.41|>=3.0.0,<3.1.0|>=3.1.0,<3.2.0|>=3.2.0,<3.3.0|>=3.3.0,<3.3.17|>=3.4.0,<3.4.11|>=4.0.0,<4.0.11 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [HIGH] CVE-2018-11385: Session Fixation Issue for Guard AuthenticationPKSA-zzvm-fw3r-ytm8 CVE-2018-11385 GHSA-g4rg-rw65-8hfg Affected version: >=2.0.0,<2.1.0|>=2.1.0,<2.2.0|>=2.2.0,<2.3.0|>=2.3.0,<2.4.0|>=2.4.0,<2.5.0|>=2.5.0,<2.6.0|>=2.6.0,<2.7.0|>=2.7.0,<2.7.48|>=2.8.0,<2.8.41|>=3.0.0,<3.1.0|>=3.1.0,<3.2.0|>=3.2.0,<3.3.0|>=3.3.0,<3.3.17|>=3.4.0,<3.4.11|>=4.0.0,<4.0.11 Reported by: 
 GitHub, FriendsOfPHP/security-advisories