Количество 378
Количество 378
GHSA-qmqw-mpqp-mr54
Symfony Incorrect Access Control
GHSA-qc95-4862-92fh
Symfony has an HtmlSanitizer allowLinkHosts() / allowMediaHosts() Bypass via URL-Parser Differentials and <area> Misclassification
GHSA-q8j7-fjh7-25v5
Symfony collectionCascaded and collectionCascadedDeeply fields security bypass
GHSA-q8hg-pf8v-cxrv
Symfony Http-Kernel has non-constant time comparison in UriSigner
GHSA-q87v-q8fw-gmj5
Symfony Incorrect Access Control
GHSA-q3j3-w37x-hq2q
Webcache Poisoning in symfony/http-kernel
GHSA-ph86-p8f6-f9r2
Symfony Vulnerable to Identity Spoofing via Unanchored DN Regex in X509Authenticator
GHSA-mrqx-rp3w-jpjp
Symfony vulnerable to open redirect via browser-sanitized URLs
GHSA-mm4c-ww47-3x4c
** DISPUTED ** The debug handler in Symfony before v2.7.33, 2.8.x before v2.8.26, 3.x before v3.2.13, and 3.3.x before v3.3.6 has XSS via an array key during exception pretty printing in ExceptionHandler.php, as demonstrated by a /_debugbar/open?op=get URI. NOTE: the vendor's position is that this is not a vulnerability because the debug tools are not intended for production use. NOTE: the Symfony Debug component is used by Laravel Debugbar.
GHSA-mjcw-3g32-5p52
** DISPUTED ** Reflected Cross-site scripting (XSS) vulnerability in the web profiler in SensioLabs Symfony 3.3.6 allows remote attackers to inject arbitrary web script or HTML via the "file" parameter, aka an _profiler/open?file= URI. NOTE: The vendor states "The XSS ... is in the web profiler, a tool that should never be deployed in production (so, we don't handle those issues as security issues)."
GHSA-mcx4-f5f5-4859
Prevent cache poisoning via a Response Content-Type header in Symfony
GHSA-m884-279h-32v2
Exceptions displayed in non-debug configurations in Symfony
GHSA-m7v2-7gxm-vc2v
Symfony has Unauthenticated PHP Object Deserialization in MonologBridge server:log Listener
GHSA-m2wj-r6g3-fxfx
Symfony possible session fixation vulnerability
GHSA-jjx5-fq5g-8xpc
Symfony Cryptographic Vulnerability
GHSA-j8gj-9rm5-4xhx
Symfony's Cas2Handler Derives CAS service URL from Client Host Header → Cross-Service Ticket Replay
GHSA-j5jh-hpr4-h332
Symfony Session Fixation Vulnerability
GHSA-hmr5-2xcr-v8pp
Symfony Vulnerable to stored XSS in WebProfiler CodeExtension::fileExcerpt() — Unescaped Non-PHP File Rendering
GHSA-hhg7-c65m-h7ff
Symfony's HtmlSanitizer UrlAttributeSanitizer Omits action/formaction/poster/cite — `javascript`: URI Survives Sanitization (XSS)
GHSA-hf4c-m2jg-33qx
lib/form/sfForm.class.php in Symfony CMS before 1.4.20 allows remote attackers to read arbitrary files via a crafted upload request.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-qmqw-mpqp-mr54 Symfony Incorrect Access Control | 8% Низкий | около 4 лет назад | ||
GHSA-qc95-4862-92fh Symfony has an HtmlSanitizer allowLinkHosts() / allowMediaHosts() Bypass via URL-Parser Differentials and <area> Misclassification | 0% Низкий | 2 месяца назад | ||
GHSA-q8j7-fjh7-25v5 Symfony collectionCascaded and collectionCascadedDeeply fields security bypass | CVSS3: 8.1 | 1% Низкий | около 4 лет назад | |
GHSA-q8hg-pf8v-cxrv Symfony Http-Kernel has non-constant time comparison in UriSigner | CVSS3: 8.1 | 1% Низкий | больше 4 лет назад | |
GHSA-q87v-q8fw-gmj5 Symfony Incorrect Access Control | CVSS3: 9.8 | 2% Низкий | около 4 лет назад | |
GHSA-q3j3-w37x-hq2q Webcache Poisoning in symfony/http-kernel | CVSS3: 6.5 | 1% Низкий | больше 4 лет назад | |
GHSA-ph86-p8f6-f9r2 Symfony Vulnerable to Identity Spoofing via Unanchored DN Regex in X509Authenticator | 0% Низкий | 2 месяца назад | ||
GHSA-mrqx-rp3w-jpjp Symfony vulnerable to open redirect via browser-sanitized URLs | CVSS3: 3.1 | 1% Низкий | больше 1 года назад | |
GHSA-mm4c-ww47-3x4c ** DISPUTED ** The debug handler in Symfony before v2.7.33, 2.8.x before v2.8.26, 3.x before v3.2.13, and 3.3.x before v3.3.6 has XSS via an array key during exception pretty printing in ExceptionHandler.php, as demonstrated by a /_debugbar/open?op=get URI. NOTE: the vendor's position is that this is not a vulnerability because the debug tools are not intended for production use. NOTE: the Symfony Debug component is used by Laravel Debugbar. | CVSS3: 6.1 | 6% Низкий | около 4 лет назад | |
GHSA-mjcw-3g32-5p52 ** DISPUTED ** Reflected Cross-site scripting (XSS) vulnerability in the web profiler in SensioLabs Symfony 3.3.6 allows remote attackers to inject arbitrary web script or HTML via the "file" parameter, aka an _profiler/open?file= URI. NOTE: The vendor states "The XSS ... is in the web profiler, a tool that should never be deployed in production (so, we don't handle those issues as security issues)." | CVSS3: 6.1 | 1% Низкий | около 4 лет назад | |
GHSA-mcx4-f5f5-4859 Prevent cache poisoning via a Response Content-Type header in Symfony | CVSS3: 2.6 | 1% Низкий | больше 6 лет назад | |
GHSA-m884-279h-32v2 Exceptions displayed in non-debug configurations in Symfony | CVSS3: 4.6 | 1% Низкий | больше 6 лет назад | |
GHSA-m7v2-7gxm-vc2v Symfony has Unauthenticated PHP Object Deserialization in MonologBridge server:log Listener | 0% Низкий | 2 месяца назад | ||
GHSA-m2wj-r6g3-fxfx Symfony possible session fixation vulnerability | CVSS3: 6.5 | 1% Низкий | больше 2 лет назад | |
GHSA-jjx5-fq5g-8xpc Symfony Cryptographic Vulnerability | CVSS3: 7.5 | 2% Низкий | около 4 лет назад | |
GHSA-j8gj-9rm5-4xhx Symfony's Cas2Handler Derives CAS service URL from Client Host Header → Cross-Service Ticket Replay | 0% Низкий | 2 месяца назад | ||
GHSA-j5jh-hpr4-h332 Symfony Session Fixation Vulnerability | CVSS3: 3.1 | 3% Низкий | около 4 лет назад | |
GHSA-hmr5-2xcr-v8pp Symfony Vulnerable to stored XSS in WebProfiler CodeExtension::fileExcerpt() — Unescaped Non-PHP File Rendering | 0% Низкий | 2 месяца назад | ||
GHSA-hhg7-c65m-h7ff Symfony's HtmlSanitizer UrlAttributeSanitizer Omits action/formaction/poster/cite — `javascript`: URI Survives Sanitization (XSS) | 0% Низкий | 2 месяца назад | ||
GHSA-hf4c-m2jg-33qx lib/form/sfForm.class.php in Symfony CMS before 1.4.20 allows remote attackers to read arbitrary files via a crafted upload request. | 3% Низкий | около 4 лет назад |
Уязвимостей на страницу