CVE-2023-46735: Symfony potential Cross-site Scripting in WebhookController
Description
The error message in WebhookController returns unescaped user-submitted input.
Resolution
WebhookController now doesn't return any user-submitted input in its response.
The patch for this issue is available here for branch 6.3.
Credits
We would like to thank Maxime Aknin for reporting the issue and to Nicolas Grekas for providing the fix.
Other sources
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Starting in version 6.0.0 and prior to version 6.3.8, the error message in WebhookController returns unescaped user-submitted input. As of version 6.3.8, WebhookController now doesn't return any user-submitted input in its response.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-46735.
What is the severity of CVE-2023-46735?
The severity of CVE-2023-46735 is medium with a severity value of 6.1.
Which software is affected by CVE-2023-46735?
The software affected by CVE-2023-46735 is Symfony and Symfony Webhook.
How can I resolve CVE-2023-46735?
To resolve CVE-2023-46735, update to Symfony version 6.3.8 or newer.
Where can I find more information about CVE-2023-46735?
You can find more information about CVE-2023-46735 in the references provided: [GitHub Security Advisory](https://github.com/symfony/symfony/security/advisories/GHSA-72x2-5c85-6wmr), [GitHub Commit](https://github.com/symfony/symfony/commit/8128c302430394f639e818a7103b3f6815d8d962), [NVD](https://nvd.nist.gov/vuln/detail/CVE-2023-46735).