Search CVE reports


Toggle filters

1 – 10 of 59 results


CVE-2024-36610

Medium priority
Needs evaluation

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.

1 affected package

symfony

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
symfony Not affected Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2024-36611

Medium priority
Ignored

In Symfony v7.07, a security vulnerability was identified in the FormLoginAuthenticator component, where it failed to adequately handle cases where the username or password field of a login request is empty. This flaw could lead...

1 affected package

symfony

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
symfony Ignored Ignored Ignored Ignored Ignored
Show less packages

CVE-2024-51996

Medium priority

Some fixes available 1 of 4

Symphony process is a module for the Symphony PHP framework which executes commands in sub-processes. When consuming a persisted remember-me cookie, Symfony does not check if the username persisted in the database matches the...

1 affected package

symfony

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
symfony Fixed Needs evaluation Needs evaluation Not affected Not affected
Show less packages

CVE-2024-51736

Medium priority
Not affected

Symphony process is a module for the Symphony PHP framework which executes commands in sub-processes. On Windows, when an executable file named `cmd.exe` is located in the current working directory it will be called by the...

1 affected package

symfony

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
symfony Not affected Not affected Not affected Not affected Not affected
Show less packages

CVE-2024-50345

Medium priority

Some fixes available 3 of 6

symfony/http-foundation is a module for the Symphony PHP framework which defines an object-oriented layer for the HTTP specification. The `Request` class, does not parse URI with special characters the same way browsers do. As a...

1 affected package

symfony

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
symfony Fixed Fixed Fixed Vulnerable Vulnerable
Show less packages

CVE-2024-50343

Medium priority

Some fixes available 3 of 6

symfony/validator is a module for the Symphony PHP framework which provides tools to validate values. It is possible to trick a `Validator` configured with a regular expression using the `$` metacharacters, with an input ending...

1 affected package

symfony

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
symfony Fixed Fixed Fixed Vulnerable Vulnerable
Show less packages

CVE-2024-50342

Medium priority

Some fixes available 2 of 4

symfony/http-client is a module for the Symphony PHP framework which provides powerful methods to fetch HTTP resources synchronously or asynchronously. When using the `NoPrivateNetworkHttpClient`, some internal information is...

1 affected package

symfony

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
symfony Fixed Fixed Needs evaluation Not affected Not affected
Show less packages

CVE-2024-50341

Medium priority
Fixed

symfony/security-bundle is a module for the Symphony PHP framework which provides a tight integration of the Security component into the Symfony full-stack framework. The custom `user_checker` defined on a firewall is not called...

1 affected package

symfony

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
symfony Fixed Not affected Not affected Not affected Not affected
Show less packages

CVE-2024-50340

Medium priority

Some fixes available 2 of 4

symfony/runtime is a module for the Symphony PHP framework which enables decoupling PHP applications from global state. When the `register_argv_argc` php directive is set to `on` , and users call any URL with a special crafted...

1 affected package

symfony

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
symfony Fixed Fixed Needs evaluation Not affected Not affected
Show less packages

CVE-2023-46735

Medium priority
Ignored

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Starting in version 6.0.0 and prior to version 6.3.8, the error message in `WebhookController` returns unescaped user-submitted...

1 affected package

symfony

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
symfony Not affected Not affected Not affected Not affected Not affected
Show less packages