Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2023-46734

Опубликовано: 10 нояб. 2023
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 6.1

Описание

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Starting in versions 2.0.0, 5.0.0, and 6.0.0 and prior to versions 4.4.51, 5.4.31, and 6.3.8, some Twig filters in CodeExtension use is_safe=html but don't actually ensure their input is safe. As of versions 4.4.51, 5.4.31, and 6.3.8, Symfony now escapes the output of the affected filters.

РелизСтатусПримечание
bionic

ignored

end of standard support
devel

not-affected

6.4.5+dfsg-3ubuntu3
esm-apps-legacy/xenial

needed

esm-apps/bionic

needed

esm-apps/focal

released

4.3.8+dfsg-1ubuntu1+esm2
esm-apps/jammy

released

5.4.4+dfsg-1ubuntu8+esm1
esm-apps/noble

not-affected

6.4.5+dfsg-3ubuntu3
esm-apps/resolute

not-affected

6.4.5+dfsg-3ubuntu3
esm-apps/xenial

ignored

end of ESM support, was needed
focal

ignored

end of standard support, was needed

Показывать по

EPSS

Процентиль: 51%
0.00682
Низкий

6.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
nvd
почти 3 года назад

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Starting in versions 2.0.0, 5.0.0, and 6.0.0 and prior to versions 4.4.51, 5.4.31, and 6.3.8, some Twig filters in CodeExtension use `is_safe=html` but don't actually ensure their input is safe. As of versions 4.4.51, 5.4.31, and 6.3.8, Symfony now escapes the output of the affected filters.

CVSS3: 6.1
debian
почти 3 года назад

Symfony is a PHP framework for web and console applications and a set ...

CVSS3: 6.1
github
почти 3 года назад

Symfony potential Cross-site Scripting vulnerabilities in CodeExtension filters

CVSS3: 6.1
fstec
почти 3 года назад

Уязвимость программной платформы для разработки и управления веб-приложениями Symfony, позволяющая нарушителю раскрыть защищаемую информацию, выполнить фишинговые атаки и атаки с диск-загрузкой

CVSS3: 9.8
redos
около 2 лет назад

Множественные уязвимости php-symfony4

EPSS

Процентиль: 51%
0.00682
Низкий

6.1 Medium

CVSS3