Search CVE reports


Toggle filters

41 – 50 of 59 results


CVE-2018-14774

Medium priority
Vulnerable

An issue was discovered in HttpKernel in Symfony 2.7.0 through 2.7.48, 2.8.0 through 2.8.43, 3.3.0 through 3.3.17, 3.4.0 through 3.4.13, 4.0.0 through 4.0.13, and 4.1.0 through 4.1.2. When using HttpCache, the values of the...

1 affected package

symfony

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
symfony Not affected Not affected Not affected Vulnerable Vulnerable
Show less packages

CVE-2018-14773

Medium priority
Vulnerable

An issue was discovered in Http Foundation in Symfony 2.7.0 through 2.7.48, 2.8.0 through 2.8.43, 3.3.0 through 3.3.17, 3.4.0 through 3.4.13, 4.0.0 through 4.0.13, and 4.1.0 through 4.1.2. It arises from support for a (legacy) IIS...

1 affected package

symfony

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
symfony Not affected Not affected Not affected Vulnerable Vulnerable
Show less packages

CVE-2017-18343

Medium priority
Ignored

** DISPUTED ** The debug handler in Symfony before v2.7.33, 2.8.x before v2.8.26, 3.x before v3.2.13, and 3.3.x before v3.3.6 has XSS via an array key during exception pretty printing in ExceptionHandler.php, as demonstrated by a...

1 affected package

symfony

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
symfony Not affected Not affected Not affected Not affected Not affected
Show less packages

CVE-2018-12040

Negligible priority
Ignored

** DISPUTED ** Reflected Cross-site scripting (XSS) vulnerability in the web profiler in SensioLabs Symfony 3.3.6 allows remote attackers to inject arbitrary web script or HTML via the "file" parameter, aka an _profiler/open?file=...

1 affected package

symfony

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
symfony Not affected Not affected Not affected Not affected Not affected
Show less packages

CVE-2018-11408

Low priority
Vulnerable

The security handlers in the Security component in Symfony in 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x before 4.0.11 have an Open redirect vulnerability when security.http_utils...

1 affected package

symfony

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
symfony Not affected Not affected Not affected Vulnerable Vulnerable
Show less packages

CVE-2018-11407

Medium priority

Some fixes available 1 of 2

An issue was discovered in the Ldap component in Symfony 2.8.x before 2.8.37, 3.3.x before 3.3.17, 3.4.x before 3.4.7, and 4.0.x before 4.0.7. It allows remote attackers to bypass authentication by logging in with a "null"...

1 affected package

symfony

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
symfony Not affected Not affected Fixed Not affected
Show less packages

CVE-2018-11406

Medium priority
Vulnerable

An issue was discovered in the Security component in Symfony 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x before 4.0.11. By default, a user's session is invalidated when the user is...

1 affected package

symfony

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
symfony Not affected Not affected Not affected Vulnerable Vulnerable
Show less packages

CVE-2018-11386

Medium priority

Some fixes available 1 of 2

An issue was discovered in the HttpFoundation component in Symfony 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x before 4.0.11. The PDOSessionHandler class allows storing sessions on...

1 affected package

symfony

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
symfony Fixed Not affected
Show less packages

CVE-2018-11385

Medium priority
Vulnerable

An issue was discovered in the Security component in Symfony 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x before 4.0.11. A session fixation vulnerability within the "Guard" login...

1 affected package

symfony

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
symfony Not affected Not affected Not affected Vulnerable Vulnerable
Show less packages

CVE-2017-16652

Medium priority
Vulnerable

An issue was discovered in Symfony 2.7.x before 2.7.38, 2.8.x before 2.8.31, 3.2.x before 3.2.14, and 3.3.x before 3.3.13. DefaultAuthenticationSuccessHandler or DefaultAuthenticationFailureHandler takes the content of the...

1 affected package

symfony

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
symfony Not affected Not affected Not affected Not affected Vulnerable
Show less packages