Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-72x2-5c85-6wmr

Опубликовано: 12 нояб. 2023
Источник: github
Github: Прошло ревью
CVSS4: 5.3
CVSS3: 6.1

Описание

Symfony potential Cross-site Scripting in WebhookController

Description

The error message in WebhookController returns unescaped user-submitted input.

Resolution

WebhookController now doesn't return any user-submitted input in its response.

The patch for this issue is available here for branch 6.3.

Credits

We would like to thank Maxime Aknin for reporting the issue and to Nicolas Grekas for providing the fix.

Пакеты

Наименование

symfony/webhook

composer
Затронутые версииВерсия исправления

>= 6.3.0, < 6.3.8

6.3.8

Наименование

symfony/symfony

composer
Затронутые версииВерсия исправления

>= 6.3.0, < 6.3.8

6.3.8

EPSS

Процентиль: 83%
0.01936
Низкий

5.3 Medium

CVSS4

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
ubuntu
больше 1 года назад

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Starting in version 6.0.0 and prior to version 6.3.8, the error message in `WebhookController` returns unescaped user-submitted input. As of version 6.3.8, `WebhookController` now doesn't return any user-submitted input in its response.

CVSS3: 6.1
nvd
больше 1 года назад

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Starting in version 6.0.0 and prior to version 6.3.8, the error message in `WebhookController` returns unescaped user-submitted input. As of version 6.3.8, `WebhookController` now doesn't return any user-submitted input in its response.

CVSS3: 6.1
debian
больше 1 года назад

Symfony is a PHP framework for web and console applications and a set ...

EPSS

Процентиль: 83%
0.01936
Низкий

5.3 Medium

CVSS4

6.1 Medium

CVSS3

Дефекты

CWE-79