Логотип exploitDog
product: "symfony"
Консоль
Логотип exploitDog

exploitDog

product: "symfony"
Symfony

Symfonyфреймворк c открытым исходным кодом, написанный на PHP.

Релизный цикл, информация об уязвимостях

Продукт: Symfony
Вендор: SensioLabs

График релизов

5.46.16.26.37.06.47.17.27.32021202220232024202520262027202820292030

Недавние уязвимости Symfony

Количество 255

ubuntu логотип

CVE-2020-5274

больше 5 лет назад

In Symfony before versions 5.0.5 and 4.4.5, some properties of the Exception were not properly escaped when the `ErrorHandler` rendered it stacktrace. In addition, the stacktrace were displayed even in a non-debug configuration. The ErrorHandler now escape alls properties of the exception, and the stacktrace is only display in debug configuration. This issue is patched in symfony/http-foundation versions 4.4.5 and 5.0.5

CVSS3: 4.6
EPSS: Низкий
github логотип

GHSA-g4m9-5hpf-hx72

больше 5 лет назад

Firewall configured with unanimous strategy was not actually unanimous in Symfony

CVSS3: 7.6
EPSS: Низкий
github логотип

GHSA-m884-279h-32v2

больше 5 лет назад

Exceptions displayed in non-debug configurations in Symfony

CVSS3: 4.6
EPSS: Низкий
github логотип

GHSA-mcx4-f5f5-4859

больше 5 лет назад

Prevent cache poisoning via a Response Content-Type header in Symfony

CVSS3: 2.6
EPSS: Низкий
github логотип

GHSA-cchx-mfrc-fwqr

больше 5 лет назад

Improper authentication in Symfony

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-w2fr-65vp-mxw3

больше 5 лет назад

Deserialization of untrusted data in Symfony

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-w4rc-rx25-8m86

больше 5 лет назад

Improper Input Validation in Symfony

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2013-4752

почти 6 лет назад

Symfony 2.0.X before 2.0.24, 2.1.X before 2.1.12, 2.2.X before 2.2.5, and 2.3.X before 2.3.3 have an issue in the HttpFoundation component. The Host header can be manipulated by an attacker when the framework is generating an absolute URL. A remote attacker could exploit this vulnerability to inject malicious content into the Web application page and conduct various attacks.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-x92h-wmg2-6hp7

почти 6 лет назад

Invalid HTTP method overrides allow possible XSS or other attacks in Symfony

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4vpc-5jx4-cfqg

почти 6 лет назад

User enumeration leak using switch user functionality in Symfony

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
ubuntu логотип
CVE-2020-5274

In Symfony before versions 5.0.5 and 4.4.5, some properties of the Exception were not properly escaped when the `ErrorHandler` rendered it stacktrace. In addition, the stacktrace were displayed even in a non-debug configuration. The ErrorHandler now escape alls properties of the exception, and the stacktrace is only display in debug configuration. This issue is patched in symfony/http-foundation versions 4.4.5 and 5.0.5

CVSS3: 4.6
0%
Низкий
больше 5 лет назад
github логотип
GHSA-g4m9-5hpf-hx72

Firewall configured with unanimous strategy was not actually unanimous in Symfony

CVSS3: 7.6
0%
Низкий
больше 5 лет назад
github логотип
GHSA-m884-279h-32v2

Exceptions displayed in non-debug configurations in Symfony

CVSS3: 4.6
0%
Низкий
больше 5 лет назад
github логотип
GHSA-mcx4-f5f5-4859

Prevent cache poisoning via a Response Content-Type header in Symfony

CVSS3: 2.6
0%
Низкий
больше 5 лет назад
github логотип
GHSA-cchx-mfrc-fwqr

Improper authentication in Symfony

CVSS3: 7.5
0%
Низкий
больше 5 лет назад
github логотип
GHSA-w2fr-65vp-mxw3

Deserialization of untrusted data in Symfony

CVSS3: 7.1
1%
Низкий
больше 5 лет назад
github логотип
GHSA-w4rc-rx25-8m86

Improper Input Validation in Symfony

CVSS3: 9.8
5%
Низкий
больше 5 лет назад
nvd логотип
CVE-2013-4752

Symfony 2.0.X before 2.0.24, 2.1.X before 2.1.12, 2.2.X before 2.2.5, and 2.3.X before 2.3.3 have an issue in the HttpFoundation component. The Host header can be manipulated by an attacker when the framework is generating an absolute URL. A remote attacker could exploit this vulnerability to inject malicious content into the Web application page and conduct various attacks.

CVSS3: 6.1
1%
Низкий
почти 6 лет назад
github логотип
GHSA-x92h-wmg2-6hp7

Invalid HTTP method overrides allow possible XSS or other attacks in Symfony

CVSS3: 9.8
0%
Низкий
почти 6 лет назад
github логотип
GHSA-4vpc-5jx4-cfqg

User enumeration leak using switch user functionality in Symfony

CVSS3: 5.3
2%
Низкий
почти 6 лет назад

Уязвимостей на страницу


Поделиться