PKSA-3grm-n326-q5z3 Security Advisory

  • [HIGH] CVE-2018-11406: CSRF Token Fixation

    PKSA-3grm-n326-q5z3 CVE-2018-11406 GHSA-g4g7-q726-v5hg

    Affected package: symfony/security

    Affected version: >=2.0.0,<2.1.0|>=2.1.0,<2.2.0|>=2.2.0,<2.3.0|>=2.3.0,<2.4.0|>=2.4.0,<2.5.0|>=2.5.0,<2.6.0|>=2.6.0,<2.7.0|>=2.7.0,<2.7.48|>=2.8.0,<2.8.41|>=3.0.0,<3.1.0|>=3.1.0,<3.2.0|>=3.2.0,<3.3.0|>=3.3.0,<3.3.17|>=3.4.0,<3.4.11|>=4.0.0,<4.0.11

    Reported by:
    GitHub, FriendsOfPHP/security-advisories