Search CVE reports


Toggle filters

41 – 50 of 59 results


CVE-2018-11407

Medium priority

Some fixes available 1 of 2

An issue was discovered in the Ldap component in Symfony 2.8.x before 2.8.37, 3.3.x before 3.3.17, 3.4.x before 3.4.7, and 4.0.x before 4.0.7. It allows remote attackers to bypass authentication by logging in with a "null"...

1 affected package

symfony

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
symfony Not affected Not affected Fixed
Show less packages

CVE-2018-11406

Medium priority
Vulnerable

An issue was discovered in the Security component in Symfony 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x before 4.0.11. By default, a user's session is invalidated when the user is...

1 affected package

symfony

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
symfony Not affected Not affected Not affected Vulnerable
Show less packages

CVE-2018-11386

Medium priority

Some fixes available 1 of 2

An issue was discovered in the HttpFoundation component in Symfony 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x before 4.0.11. The PDOSessionHandler class allows storing sessions on...

1 affected package

symfony

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
symfony Fixed
Show less packages

CVE-2018-11385

Medium priority
Vulnerable

An issue was discovered in the Security component in Symfony 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x before 4.0.11. A session fixation vulnerability within the "Guard" login...

1 affected package

symfony

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
symfony Not affected Not affected Not affected Vulnerable
Show less packages

CVE-2017-18343

Medium priority
Ignored

The debug handler in Symfony before v2.7.33, 2.8.x before v2.8.26, 3.x before v3.2.13, and 3.3.x before v3.3.6 has XSS via an array key during exception pretty printing in ExceptionHandler.php, as demonstrated by...

1 affected package

symfony

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
symfony Not affected Not affected Not affected Not affected
Show less packages

CVE-2017-16790

Medium priority
Vulnerable

An issue was discovered in Symfony before 2.7.38, 2.8.31, 3.2.14, 3.3.13, 3.4-BETA5, and 4.0-BETA5. When a form is submitted by the user, the request handler classes of the Form component merge POST data and uploaded files data...

1 affected package

symfony

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
symfony Not affected Not affected Not affected Not affected
Show less packages

CVE-2017-16654

Medium priority
Vulnerable

An issue was discovered in Symfony before 2.7.38, 2.8.31, 3.2.14, 3.3.13, 3.4-BETA5, and 4.0-BETA5. The Intl component includes various bundle readers that are used to read resource bundles from the local filesystem. The read()...

1 affected package

symfony

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
symfony Not affected Not affected Not affected Not affected
Show less packages

CVE-2017-16653

Medium priority
Vulnerable

An issue was discovered in Symfony before 2.7.38, 2.8.31, 3.2.14, 3.3.13, 3.4-BETA5, and 4.0-BETA5. The current implementation of CSRF protection in Symfony (Version >=2) does not use different tokens for HTTP and HTTPS; therefore...

1 affected package

symfony

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
symfony Not affected Not affected Not affected Not affected
Show less packages

CVE-2017-16652

Medium priority
Vulnerable

An issue was discovered in Symfony 2.7.x before 2.7.38, 2.8.x before 2.8.31, 3.2.x before 3.2.14, and 3.3.x before 3.3.13. DefaultAuthenticationSuccessHandler or DefaultAuthenticationFailureHandler takes the content of the...

1 affected package

symfony

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
symfony Not affected Not affected Not affected Not affected
Show less packages

CVE-2017-11365

Medium priority
Not affected

Certain Symfony products are affected by: Incorrect Access Control. This affects Symfony 2.7.30 and Symfony 2.8.23 and Symfony 3.2.10 and Symfony 3.3.3. The type of exploitation is: remote. The component is: Password validator.

1 affected package

symfony

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
symfony Not affected
Show less packages