Логотип exploitDog
product: "symfony"
Консоль
Логотип exploitDog

exploitDog

product: "symfony"

Количество 263

Количество 263

nvd логотип

CVE-2012-2667

больше 13 лет назад

Session fixation vulnerability in lib/user/sfBasicSecurityUser.class.php in SensioLabs Symfony before 1.4.18 allows remote attackers to hijack web sessions via vectors related to the regenerate method and unspecified "database backed session classes."

CVSS2: 4.3
EPSS: Низкий
fstec логотип

BDU:2024-10934

почти 2 года назад

Уязвимость класса FormLoginAuthenticator программной платформы для разработки и управления веб-приложениями Symfony, позволяющая нарушителю обойти процедуру аутентификации и вызвать отказ в обслуживании

CVSS3: 7.5
EPSS: Низкий
fstec логотип

BDU:2023-08236

около 2 лет назад

Уязвимость функции SessionStrategyListener программной платформы для разработки и управления веб-приложениями Symfony, позволяющая нарушителю оказать воздействие на целостность защищаемой информации

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-q847-2q57-wmr3

около 2 лет назад

Symfony potential Cross-site Scripting vulnerabilities in CodeExtension filters

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-pgwj-prpq-jpc2

около 6 лет назад

Symfony Service IDs Allow Injection

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-g996-q5r8-w7g2

около 6 лет назад

Symfony Cross-site Scripting (XSS) vulnerability

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-cchx-mfrc-fwqr

почти 6 лет назад

Improper authentication in Symfony

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-8wgj-6wx8-h5hq

больше 3 лет назад

Symfony HTTP Foundation web cache poisoning

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-754h-5r27-7x3r

больше 5 лет назад

RCE in Symfony

CVSS3: 8
EPSS: Низкий
github логотип

GHSA-3rg7-wf37-54rm

3 месяца назад

Symfony's incorrect parsing of PATH_INFO can lead to limited authorization bypass

CVSS3: 7.3
EPSS: Низкий
ubuntu логотип

CVE-2025-64500

3 месяца назад

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Symfony's HttpFoundation component defines an object-oriented layer for the HTTP specification. Starting in version 2.0.0 and prior to version 5.4.50, 6.4.29, and 7.3.7, the `Request` class improperly interprets some `PATH_INFO` in a way that leads to representing some URLs with a path that doesn't start with a `/`. This can allow bypassing some access control rules that are built with this `/`-prefix assumption. Starting in versions 5.4.50, 6.4.29, and 7.3.7, the `Request` class now ensures that URL paths always start with a `/`.

CVSS3: 7.3
EPSS: Низкий
nvd логотип

CVE-2025-64500

3 месяца назад

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Symfony's HttpFoundation component defines an object-oriented layer for the HTTP specification. Starting in version 2.0.0 and prior to version 5.4.50, 6.4.29, and 7.3.7, the `Request` class improperly interprets some `PATH_INFO` in a way that leads to representing some URLs with a path that doesn't start with a `/`. This can allow bypassing some access control rules that are built with this `/`-prefix assumption. Starting in versions 5.4.50, 6.4.29, and 7.3.7, the `Request` class now ensures that URL paths always start with a `/`.

CVSS3: 7.3
EPSS: Низкий
debian логотип

CVE-2025-64500

3 месяца назад

Symfony is a PHP framework for web and console applications and a set ...

CVSS3: 7.3
EPSS: Низкий
ubuntu логотип

CVE-2023-46734

около 2 лет назад

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Starting in versions 2.0.0, 5.0.0, and 6.0.0 and prior to versions 4.4.51, 5.4.31, and 6.3.8, some Twig filters in CodeExtension use `is_safe=html` but don't actually ensure their input is safe. As of versions 4.4.51, 5.4.31, and 6.3.8, Symfony now escapes the output of the affected filters.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2023-46734

около 2 лет назад

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Starting in versions 2.0.0, 5.0.0, and 6.0.0 and prior to versions 4.4.51, 5.4.31, and 6.3.8, some Twig filters in CodeExtension use `is_safe=html` but don't actually ensure their input is safe. As of versions 4.4.51, 5.4.31, and 6.3.8, Symfony now escapes the output of the affected filters.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2023-46734

около 2 лет назад

Symfony is a PHP framework for web and console applications and a set ...

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2020-15094

больше 5 лет назад

In Symfony before versions 4.4.13 and 5.1.5, the CachingHttpClient class from the HttpClient Symfony component relies on the HttpCache class to handle requests. HttpCache uses internal headers like X-Body-Eval and X-Body-File to control the restoration of cached responses. The class was initially written with surrogate caching and ESI support in mind (all HTTP calls come from a trusted backend in that scenario). But when used by CachingHttpClient and if an attacker can control the response for a request being made by the CachingHttpClient, remote code execution is possible. This has been fixed in versions 4.4.13 and 5.1.5.

CVSS3: 8
EPSS: Низкий
nvd логотип

CVE-2020-15094

больше 5 лет назад

In Symfony before versions 4.4.13 and 5.1.5, the CachingHttpClient class from the HttpClient Symfony component relies on the HttpCache class to handle requests. HttpCache uses internal headers like X-Body-Eval and X-Body-File to control the restoration of cached responses. The class was initially written with surrogate caching and ESI support in mind (all HTTP calls come from a trusted backend in that scenario). But when used by CachingHttpClient and if an attacker can control the response for a request being made by the CachingHttpClient, remote code execution is possible. This has been fixed in versions 4.4.13 and 5.1.5.

CVSS3: 8
EPSS: Низкий
debian логотип

CVE-2020-15094

больше 5 лет назад

In Symfony before versions 4.4.13 and 5.1.5, the CachingHttpClient cla ...

CVSS3: 8
EPSS: Низкий
ubuntu логотип

CVE-2019-10911

больше 6 лет назад

In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, a vulnerability would allow an attacker to authenticate as a privileged user on sites with user registration and remember me login functionality enabled. This is related to symfony/security.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2012-2667

Session fixation vulnerability in lib/user/sfBasicSecurityUser.class.php in SensioLabs Symfony before 1.4.18 allows remote attackers to hijack web sessions via vectors related to the regenerate method and unspecified "database backed session classes."

CVSS2: 4.3
1%
Низкий
больше 13 лет назад
fstec логотип
BDU:2024-10934

Уязвимость класса FormLoginAuthenticator программной платформы для разработки и управления веб-приложениями Symfony, позволяющая нарушителю обойти процедуру аутентификации и вызвать отказ в обслуживании

CVSS3: 7.5
0%
Низкий
почти 2 года назад
fstec логотип
BDU:2023-08236

Уязвимость функции SessionStrategyListener программной платформы для разработки и управления веб-приложениями Symfony, позволяющая нарушителю оказать воздействие на целостность защищаемой информации

CVSS3: 6.5
1%
Низкий
около 2 лет назад
github логотип
GHSA-q847-2q57-wmr3

Symfony potential Cross-site Scripting vulnerabilities in CodeExtension filters

CVSS3: 6.1
1%
Низкий
около 2 лет назад
github логотип
GHSA-pgwj-prpq-jpc2

Symfony Service IDs Allow Injection

CVSS3: 9.8
13%
Средний
около 6 лет назад
github логотип
GHSA-g996-q5r8-w7g2

Symfony Cross-site Scripting (XSS) vulnerability

CVSS3: 5.4
0%
Низкий
около 6 лет назад
github логотип
GHSA-cchx-mfrc-fwqr

Improper authentication in Symfony

CVSS3: 7.5
0%
Низкий
почти 6 лет назад
github логотип
GHSA-8wgj-6wx8-h5hq

Symfony HTTP Foundation web cache poisoning

CVSS3: 6.5
4%
Низкий
больше 3 лет назад
github логотип
GHSA-754h-5r27-7x3r

RCE in Symfony

CVSS3: 8
2%
Низкий
больше 5 лет назад
github логотип
GHSA-3rg7-wf37-54rm

Symfony's incorrect parsing of PATH_INFO can lead to limited authorization bypass

CVSS3: 7.3
0%
Низкий
3 месяца назад
ubuntu логотип
CVE-2025-64500

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Symfony's HttpFoundation component defines an object-oriented layer for the HTTP specification. Starting in version 2.0.0 and prior to version 5.4.50, 6.4.29, and 7.3.7, the `Request` class improperly interprets some `PATH_INFO` in a way that leads to representing some URLs with a path that doesn't start with a `/`. This can allow bypassing some access control rules that are built with this `/`-prefix assumption. Starting in versions 5.4.50, 6.4.29, and 7.3.7, the `Request` class now ensures that URL paths always start with a `/`.

CVSS3: 7.3
0%
Низкий
3 месяца назад
nvd логотип
CVE-2025-64500

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Symfony's HttpFoundation component defines an object-oriented layer for the HTTP specification. Starting in version 2.0.0 and prior to version 5.4.50, 6.4.29, and 7.3.7, the `Request` class improperly interprets some `PATH_INFO` in a way that leads to representing some URLs with a path that doesn't start with a `/`. This can allow bypassing some access control rules that are built with this `/`-prefix assumption. Starting in versions 5.4.50, 6.4.29, and 7.3.7, the `Request` class now ensures that URL paths always start with a `/`.

CVSS3: 7.3
0%
Низкий
3 месяца назад
debian логотип
CVE-2025-64500

Symfony is a PHP framework for web and console applications and a set ...

CVSS3: 7.3
0%
Низкий
3 месяца назад
ubuntu логотип
CVE-2023-46734

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Starting in versions 2.0.0, 5.0.0, and 6.0.0 and prior to versions 4.4.51, 5.4.31, and 6.3.8, some Twig filters in CodeExtension use `is_safe=html` but don't actually ensure their input is safe. As of versions 4.4.51, 5.4.31, and 6.3.8, Symfony now escapes the output of the affected filters.

CVSS3: 6.1
1%
Низкий
около 2 лет назад
nvd логотип
CVE-2023-46734

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Starting in versions 2.0.0, 5.0.0, and 6.0.0 and prior to versions 4.4.51, 5.4.31, and 6.3.8, some Twig filters in CodeExtension use `is_safe=html` but don't actually ensure their input is safe. As of versions 4.4.51, 5.4.31, and 6.3.8, Symfony now escapes the output of the affected filters.

CVSS3: 6.1
1%
Низкий
около 2 лет назад
debian логотип
CVE-2023-46734

Symfony is a PHP framework for web and console applications and a set ...

CVSS3: 6.1
1%
Низкий
около 2 лет назад
ubuntu логотип
CVE-2020-15094

In Symfony before versions 4.4.13 and 5.1.5, the CachingHttpClient class from the HttpClient Symfony component relies on the HttpCache class to handle requests. HttpCache uses internal headers like X-Body-Eval and X-Body-File to control the restoration of cached responses. The class was initially written with surrogate caching and ESI support in mind (all HTTP calls come from a trusted backend in that scenario). But when used by CachingHttpClient and if an attacker can control the response for a request being made by the CachingHttpClient, remote code execution is possible. This has been fixed in versions 4.4.13 and 5.1.5.

CVSS3: 8
2%
Низкий
больше 5 лет назад
nvd логотип
CVE-2020-15094

In Symfony before versions 4.4.13 and 5.1.5, the CachingHttpClient class from the HttpClient Symfony component relies on the HttpCache class to handle requests. HttpCache uses internal headers like X-Body-Eval and X-Body-File to control the restoration of cached responses. The class was initially written with surrogate caching and ESI support in mind (all HTTP calls come from a trusted backend in that scenario). But when used by CachingHttpClient and if an attacker can control the response for a request being made by the CachingHttpClient, remote code execution is possible. This has been fixed in versions 4.4.13 and 5.1.5.

CVSS3: 8
2%
Низкий
больше 5 лет назад
debian логотип
CVE-2020-15094

In Symfony before versions 4.4.13 and 5.1.5, the CachingHttpClient cla ...

CVSS3: 8
2%
Низкий
больше 5 лет назад
ubuntu логотип
CVE-2019-10911

In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, a vulnerability would allow an attacker to authenticate as a privileged user on sites with user registration and remember me login functionality enabled. This is related to symfony/security.

CVSS3: 7.5
0%
Низкий
больше 6 лет назад

Уязвимостей на страницу