CVE-2022-23601
- EPSS 0.17%
- Veröffentlicht 01.02.2022 13:15:10
- Zuletzt bearbeitet 21.11.2024 06:48:54
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. The Symfony form component provides a CSRF protection mechanism by using a random token injected in the form and using the session to store and control ...
- EPSS 0.87%
- Veröffentlicht 24.11.2021 19:15:07
- Zuletzt bearbeitet 21.11.2024 06:25:56
Symfony/Serializer handles serializing and deserializing data structures for Symfony, a PHP framework for web and console applications and a set of reusable PHP components. Symfony versions 4.1.0 before 4.4.35 and versions 5.0.0 before 5.3.12 are vul...
CVE-2021-41268
- EPSS 0.48%
- Veröffentlicht 24.11.2021 19:15:07
- Zuletzt bearbeitet 21.11.2024 06:25:55
Symfony/SecurityBundle is the security system for Symfony, a PHP framework for web and console applications and a set of reusable PHP components. Since the rework of the Remember me cookie in version 5.3.0, the cookie is not invalidated when the user...
CVE-2021-41267
- EPSS 0.46%
- Veröffentlicht 24.11.2021 19:15:07
- Zuletzt bearbeitet 21.11.2024 06:25:55
Symfony/Http-Kernel is the HTTP kernel component for Symfony, a PHP framework for web and console applications and a set of reusable PHP components. Headers that are not part of the "trusted_headers" allowed list are ignored and protect users from "C...
CVE-2021-32693
- EPSS 0.55%
- Veröffentlicht 17.06.2021 23:15:07
- Zuletzt bearbeitet 21.11.2024 06:07:32
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. A vulnerability related to firewall authentication is in Symfony starting with version 5.3.0 and prior to 5.3.2. When an application defines multiple fi...
CVE-2021-21424
- EPSS 0.27%
- Veröffentlicht 13.05.2021 16:15:07
- Zuletzt bearbeitet 21.11.2024 05:48:20
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. The ability to enumerate users was possible without relevant permissions due to different handling depending on whether the user existed or not when att...
CVE-2020-15094
- EPSS 2.25%
- Veröffentlicht 02.09.2020 18:15:11
- Zuletzt bearbeitet 21.11.2024 05:04:47
In Symfony before versions 4.4.13 and 5.1.5, the CachingHttpClient class from the HttpClient Symfony component relies on the HttpCache class to handle requests. HttpCache uses internal headers like X-Body-Eval and X-Body-File to control the restorati...
CVE-2020-5275
- EPSS 0.27%
- Veröffentlicht 30.03.2020 20:15:19
- Zuletzt bearbeitet 21.11.2024 05:33:48
In symfony/security-http before versions 4.4.7 and 5.0.7, when a `Firewall` checks access control rule, it iterate overs each rule's attributes and stops as soon as the accessDecisionManager decides to grant access on the attribute, preventing the ch...
CVE-2020-5274
- EPSS 0.27%
- Veröffentlicht 30.03.2020 20:15:19
- Zuletzt bearbeitet 21.11.2024 05:33:48
In Symfony before versions 5.0.5 and 4.4.5, some properties of the Exception were not properly escaped when the `ErrorHandler` rendered it stacktrace. In addition, the stacktrace were displayed even in a non-debug configuration. The ErrorHandler now ...
CVE-2020-5255
- EPSS 0.37%
- Veröffentlicht 30.03.2020 20:15:19
- Zuletzt bearbeitet 21.11.2024 05:33:46
In Symfony before versions 4.4.7 and 5.0.7, when a `Response` does not contain a `Content-Type` header, affected versions of Symfony can fallback to the format defined in the `Accept` header of the request, leading to a possible mismatch between the ...