Логотип exploitDog
bind:CVE-2020-5275
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-5275

Количество 4

Количество 4

ubuntu логотип

CVE-2020-5275

больше 5 лет назад

In symfony/security-http before versions 4.4.7 and 5.0.7, when a `Firewall` checks access control rule, it iterate overs each rule's attributes and stops as soon as the accessDecisionManager decides to grant access on the attribute, preventing the check of next attributes that should have been take into account in an unanimous strategy. The accessDecisionManager is now called with all attributes at once, allowing the unanimous strategy being applied on each attribute. This issue is patched in versions 4.4.7 and 5.0.7.

CVSS3: 7.6
EPSS: Низкий
nvd логотип

CVE-2020-5275

больше 5 лет назад

In symfony/security-http before versions 4.4.7 and 5.0.7, when a `Firewall` checks access control rule, it iterate overs each rule's attributes and stops as soon as the accessDecisionManager decides to grant access on the attribute, preventing the check of next attributes that should have been take into account in an unanimous strategy. The accessDecisionManager is now called with all attributes at once, allowing the unanimous strategy being applied on each attribute. This issue is patched in versions 4.4.7 and 5.0.7.

CVSS3: 7.6
EPSS: Низкий
debian логотип

CVE-2020-5275

больше 5 лет назад

In symfony/security-http before versions 4.4.7 and 5.0.7, when a `Fire ...

CVSS3: 7.6
EPSS: Низкий
github логотип

GHSA-g4m9-5hpf-hx72

больше 5 лет назад

Firewall configured with unanimous strategy was not actually unanimous in Symfony

CVSS3: 7.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2020-5275

In symfony/security-http before versions 4.4.7 and 5.0.7, when a `Firewall` checks access control rule, it iterate overs each rule's attributes and stops as soon as the accessDecisionManager decides to grant access on the attribute, preventing the check of next attributes that should have been take into account in an unanimous strategy. The accessDecisionManager is now called with all attributes at once, allowing the unanimous strategy being applied on each attribute. This issue is patched in versions 4.4.7 and 5.0.7.

CVSS3: 7.6
0%
Низкий
больше 5 лет назад
nvd логотип
CVE-2020-5275

In symfony/security-http before versions 4.4.7 and 5.0.7, when a `Firewall` checks access control rule, it iterate overs each rule's attributes and stops as soon as the accessDecisionManager decides to grant access on the attribute, preventing the check of next attributes that should have been take into account in an unanimous strategy. The accessDecisionManager is now called with all attributes at once, allowing the unanimous strategy being applied on each attribute. This issue is patched in versions 4.4.7 and 5.0.7.

CVSS3: 7.6
0%
Низкий
больше 5 лет назад
debian логотип
CVE-2020-5275

In symfony/security-http before versions 4.4.7 and 5.0.7, when a `Fire ...

CVSS3: 7.6
0%
Низкий
больше 5 лет назад
github логотип
GHSA-g4m9-5hpf-hx72

Firewall configured with unanimous strategy was not actually unanimous in Symfony

CVSS3: 7.6
0%
Низкий
больше 5 лет назад

Уязвимостей на страницу