PKSA-c7kd-tcsk-4236 Security Advisory
- 
                        [MEDIUM] CVE-2017-16653: CSRF protection does not use different tokens for HTTP and HTTPSPKSA-c7kd-tcsk-4236 CVE-2017-16653 GHSA-92x6-h2gr-8gxq Affected package: symfony/security-csrf Affected version: >=2.7.0,<2.7.38|>=2.8.0,<2.8.31|>=3.0.0,<3.1.0|>=3.1.0,<3.2.0|>=3.2.0,<3.2.14|>=3.3.0,<3.3.13 Reported by: 
 GitHub, FriendsOfPHP/security-advisories