Sensiolabs

Symfony

62 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.17%
  • Veröffentlicht 01.02.2022 13:15:10
  • Zuletzt bearbeitet 21.11.2024 06:48:54

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. The Symfony form component provides a CSRF protection mechanism by using a random token injected in the form and using the session to store and control ...

  • EPSS 0.87%
  • Veröffentlicht 24.11.2021 19:15:07
  • Zuletzt bearbeitet 21.11.2024 06:25:56

Symfony/Serializer handles serializing and deserializing data structures for Symfony, a PHP framework for web and console applications and a set of reusable PHP components. Symfony versions 4.1.0 before 4.4.35 and versions 5.0.0 before 5.3.12 are vul...

  • EPSS 0.48%
  • Veröffentlicht 24.11.2021 19:15:07
  • Zuletzt bearbeitet 21.11.2024 06:25:55

Symfony/SecurityBundle is the security system for Symfony, a PHP framework for web and console applications and a set of reusable PHP components. Since the rework of the Remember me cookie in version 5.3.0, the cookie is not invalidated when the user...

  • EPSS 0.46%
  • Veröffentlicht 24.11.2021 19:15:07
  • Zuletzt bearbeitet 21.11.2024 06:25:55

Symfony/Http-Kernel is the HTTP kernel component for Symfony, a PHP framework for web and console applications and a set of reusable PHP components. Headers that are not part of the "trusted_headers" allowed list are ignored and protect users from "C...

  • EPSS 0.55%
  • Veröffentlicht 17.06.2021 23:15:07
  • Zuletzt bearbeitet 21.11.2024 06:07:32

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. A vulnerability related to firewall authentication is in Symfony starting with version 5.3.0 and prior to 5.3.2. When an application defines multiple fi...

  • EPSS 0.27%
  • Veröffentlicht 13.05.2021 16:15:07
  • Zuletzt bearbeitet 21.11.2024 05:48:20

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. The ability to enumerate users was possible without relevant permissions due to different handling depending on whether the user existed or not when att...

  • EPSS 2.25%
  • Veröffentlicht 02.09.2020 18:15:11
  • Zuletzt bearbeitet 21.11.2024 05:04:47

In Symfony before versions 4.4.13 and 5.1.5, the CachingHttpClient class from the HttpClient Symfony component relies on the HttpCache class to handle requests. HttpCache uses internal headers like X-Body-Eval and X-Body-File to control the restorati...

  • EPSS 0.27%
  • Veröffentlicht 30.03.2020 20:15:19
  • Zuletzt bearbeitet 21.11.2024 05:33:48

In symfony/security-http before versions 4.4.7 and 5.0.7, when a `Firewall` checks access control rule, it iterate overs each rule's attributes and stops as soon as the accessDecisionManager decides to grant access on the attribute, preventing the ch...

  • EPSS 0.27%
  • Veröffentlicht 30.03.2020 20:15:19
  • Zuletzt bearbeitet 21.11.2024 05:33:48

In Symfony before versions 5.0.5 and 4.4.5, some properties of the Exception were not properly escaped when the `ErrorHandler` rendered it stacktrace. In addition, the stacktrace were displayed even in a non-debug configuration. The ErrorHandler now ...

  • EPSS 0.37%
  • Veröffentlicht 30.03.2020 20:15:19
  • Zuletzt bearbeitet 21.11.2024 05:33:46

In Symfony before versions 4.4.7 and 5.0.7, when a `Response` does not contain a `Content-Type` header, affected versions of Symfony can fallback to the format defined in the `Accept` header of the request, leading to a possible mismatch between the ...