Where
-Infinity
0
EOL
Jan 31, 2025
Support Ends
Jan 31, 2025

End of life: 1/31/2025, End of support: 1/31/2025, Latest version: 7.1.11

First published (updated )
EOL
Jan 31, 2025
Support Ends
Jan 31, 2025

End of life: 1/31/2025, End of support: 1/31/2025, Latest version: 7.1.11

First published (updated )
EOL
Jul 31, 2024
Support Ends
Jul 31, 2024

End of life: 7/31/2024, End of support: 7/31/2024, Latest version: 7.0.10

First published (updated )
EOL
Jul 31, 2024
Support Ends
Jul 31, 2024

End of life: 7/31/2024, End of support: 7/31/2024, Latest version: 7.0.10

First published (updated )
Severity
6.1
XSS
AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Description

The error message in WebhookController returns unescaped user-submitted input.

Resolution

WebhookController now doesn't return any user-submitted input in its response.

The patch for this issue is available here for branch 6.3.

Credits

We would like to thank Maxime Aknin for reporting the issue and to Nicolas Grekas for providing the fix.

1 / 2
First published (updated )
Severity
6.5
AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Description

SessionStrategyListener does not always migrate the session after a successful login. It only migrate the session when the logged-in user identifier changes. In some use cases, the user identifier doesn't change between the verification phase and the successful login, while the token itself changes from one type (partially-authenticated) to another (fully-authenticated). When this happens, the session id should be regenerated to prevent possible session fixations.

Resolution

Symfony now checks the type of the token in addition to the user identifier before deciding whether the session id should be regenerated.

The patch for this issue is available here for branch 5.4.

Credits

We would like to thank Robert Meijers for reporting the issue and providing the fix.

1 / 2
First published (updated )
Severity
6.5
Input Validation
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Impact Under certain circumstances, an attacker could successfully submit an entity id for an EntityType that is not part of the valid choices.

Affected applications are any that use:

A custom querybuilder option to limit the valid results; AND An EntityType with 'autocomplete' => true or a custom AsEntityAutocompleteField.

Under this circumstance, if an id is submitted, it is accepted even if the matching record would not be returned by the custom query built with querybuilder.

Patches

The problem has been fixed in symfony/ux-autocomplete version 2.11.2.

Workarounds Upgrade to version 2.11.2 or greater of symfony/ux-autocomplete or perform extra validation after submit to verify the selected option is valid.

1 / 2
First published (updated )
EOL
Jan 31, 2024
Support Ends
Jan 31, 2024

End of life: 1/31/2024, End of support: 1/31/2024, Latest version: 6.3.12

First published (updated )
EOL
Jan 31, 2024
Support Ends
Jan 31, 2024

End of life: 1/31/2024, End of support: 1/31/2024, Latest version: 6.3.12

First published (updated )
Severity
8.8
CSRF
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CVE-2022-24895: Possible CSRF token fixation

1 / 3
First published (updated )
Severity
8.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CVE-2022-24894: Prevent storing cookie headers in HttpCache

1 / 3
First published (updated )
EOL
Jul 31, 2023
Support Ends
Jul 31, 2023

End of life: 7/31/2023, End of support: 7/31/2023, Latest version: 6.2.14

First published (updated )
EOL
Jul 31, 2023
Support Ends
Jul 31, 2023

End of life: 7/31/2023, End of support: 7/31/2023, Latest version: 6.2.14

First published (updated )
EOL
Jan 31, 2023
Support Ends
Jan 31, 2023

End of life: 1/31/2023, End of support: 1/31/2023, Latest version: 6.1.12

First published (updated )
EOL
Jan 31, 2023
Support Ends
Jan 31, 2023

End of life: 1/31/2023, End of support: 1/31/2023, Latest version: 6.1.12

First published (updated )
Severity
8.8
CSRF
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CVE-2022-23601: CSRF token missing in forms

1 / 3
First published (updated )
EOL
Jan 31, 2023
Support Ends
Jan 31, 2023

End of life: 1/31/2023, End of support: 1/31/2023, Latest version: 6.0.20

First published (updated )
EOL
Jan 31, 2023
Support Ends
Jan 31, 2023

End of life: 1/31/2023, End of support: 1/31/2023, Latest version: 6.0.20

First published (updated )
Severity
6.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CVE-2021-41270: Prevent CSV Injection via formulas

1 / 3
First published (updated )
Severity
8.8
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVE-2021-41268: Remember me cookie persistance after password changes

1 / 3
First published (updated )
Severity
6.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

CVE-2021-41267: Webcache Poisoning via X-Forwarded-Prefix and sub-request

1 / 3
First published (updated )
Severity
8.8
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVE-2021-32693: Authentication granted to all firewalls instead of just one

1 / 3
First published (updated )
EOL
Jan 1, 2022
Support Ends
Jan 1, 2022

End of life: 1/1/2022, End of support: 1/1/2022, Latest version: 5.3.16

First published (updated )
EOL
Jan 1, 2022
Support Ends
Jan 1, 2022

End of life: 1/1/2022, End of support: 1/1/2022, Latest version: 5.3.16

First published (updated )
Severity
5.3
Infoleak
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CVE-2021-21424: Prevent user enumeration via response content in authentication mechanisms

1 / 3
First published (updated )
EOL
Jul 21, 2021
Support Ends
Jul 21, 2021

End of life: 7/21/2021, End of support: 7/21/2021, Latest version: 5.2.14

First published (updated )
EOL
Jul 21, 2021
Support Ends
Jul 21, 2021

End of life: 7/21/2021, End of support: 7/21/2021, Latest version: 5.2.14

First published (updated )
Severity
8.8
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVE-2020-15094: Prevent RCE when calling untrusted remote with CachingHttpClient

1 / 3
First published (updated )
EOL
Jan 21, 2021
Support Ends
Jan 21, 2021

End of life: 1/21/2021, End of support: 1/21/2021, Latest version: 5.1.11

First published (updated )
EOL
Jan 21, 2021
Support Ends
Jan 21, 2021

End of life: 1/21/2021, End of support: 1/21/2021, Latest version: 5.1.11

First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203