Search CVE reports


Toggle filters

21 – 30 of 59 results


CVE-2020-15094

Medium priority
Ignored

In Symfony before versions 4.4.13 and 5.1.5, the CachingHttpClient class from the HttpClient Symfony component relies on the HttpCache class to handle requests. HttpCache uses internal headers like X-Body-Eval and X-Body-File to...

1 affected package

symfony

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
symfony Not affected Not affected Not affected Not affected
Show less packages

CVE-2020-5275

Medium priority
Ignored

In symfony/security-http before versions 4.4.7 and 5.0.7, when a `Firewall` checks access control rule, it iterate overs each rule's attributes and stops as soon as the accessDecisionManager decides to grant access on...

1 affected package

symfony

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
symfony Not affected Not affected Not affected Not affected
Show less packages

CVE-2020-5274

Medium priority
Ignored

In Symfony before versions 5.0.5 and 4.4.5, some properties of the Exception were not properly escaped when the `ErrorHandler` rendered it stacktrace. In addition, the stacktrace were displayed even in a non-debug configuration....

1 affected package

symfony

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
symfony Not affected Not affected Not affected Not affected
Show less packages

CVE-2020-5255

Medium priority
Ignored

In Symfony before versions 4.4.7 and 5.0.7, when a `Response` does not contain a `Content-Type` header, affected versions of Symfony can fallback to the format defined in the `Accept` header of the request, leading to a possible...

1 affected package

symfony

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
symfony Not affected Not affected Not affected Not affected
Show less packages

CVE-2019-18889

Medium priority
Vulnerable

An issue was discovered in Symfony 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4.3.7. Serializing certain cache adapter interfaces could result in remote code injection. This is related to symfony/cache.

1 affected package

symfony

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
symfony Not affected Not affected Not affected Vulnerable Vulnerable
Show less packages

CVE-2019-18888

Medium priority
Vulnerable

An issue was discovered in Symfony 2.8.0 through 2.8.50, 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4.3.7. If an application passes unvalidated user input as the file for which MIME type validation should occur,...

1 affected package

symfony

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
symfony Not affected Not affected Not affected Vulnerable Vulnerable
Show less packages

CVE-2019-18887

Medium priority
Vulnerable

An issue was discovered in Symfony 2.8.0 through 2.8.50, 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4.3.7. The UriSigner was subject to timing attacks. This is related to symfony/http-kernel.

1 affected package

symfony

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
symfony Not affected Not affected Not affected Vulnerable Vulnerable
Show less packages

CVE-2019-11325

Medium priority
Ignored

An issue was discovered in Symfony before 4.2.12 and 4.3.x before 4.3.8. The VarExport component incorrectly escapes strings, allowing some specially crafted ones to escalate to execution of arbitrary PHP code. This is related to...

1 affected package

symfony

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
symfony Not affected Not affected Not affected Not affected
Show less packages

CVE-2019-18886

Low priority
Ignored

An issue was discovered in Symfony 4.2.0 to 4.2.11 and 4.3.0 to 4.3.7. The ability to enumerate users was possible due to different handling depending on whether the user existed when making unauthorized attempts to use the switch...

1 affected package

symfony

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
symfony Not affected Not affected Not affected Not affected
Show less packages

CVE-2017-11365

Medium priority
Not affected

Certain Symfony products are affected by: Incorrect Access Control. This affects Symfony 2.7.30 and Symfony 2.8.23 and Symfony 3.2.10 and Symfony 3.3.3. The type of exploitation is: remote. The component is: Password validator.

1 affected package

symfony

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
symfony Not affected Not affected
Show less packages