Search CVE reports


Toggle filters

41 – 50 of 84 results


CVE-2021-41270

Medium priority

Some fixes available 1 of 2

Symfony/Serializer handles serializing and deserializing data structures for Symfony, a PHP framework for web and console applications and a set of reusable PHP components. Symfony versions 4.1.0 before 4.4.35 and versions 5.0.0...

1 affected package

symfony

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
symfony Not affected Not affected Fixed Not affected
Show less packages

CVE-2021-41268

Medium priority
Ignored

Symfony/SecurityBundle is the security system for Symfony, a PHP framework for web and console applications and a set of reusable PHP components. Since the rework of the Remember me cookie in version 5.3.0, the cookie is not...

1 affected package

symfony

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
symfony Not affected Not affected Not affected
Show less packages

CVE-2021-41267

Medium priority
Ignored

Symfony/Http-Kernel is the HTTP kernel component for Symfony, a PHP framework for web and console applications and a set of reusable PHP components. Headers that are not part of the "trusted_headers" allowed list are ignored and...

1 affected package

symfony

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
symfony Not affected Not affected Not affected Not affected
Show less packages

CVE-2021-32693

Medium priority
Ignored

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. A vulnerability related to firewall authentication is in Symfony starting with version 5.3.0 and prior to 5.3.2. When an application...

1 affected package

symfony

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
symfony Not affected Not affected Not affected
Show less packages

CVE-2021-21424

Low priority

Some fixes available 2 of 4

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. The ability to enumerate users was possible without relevant permissions due to different handling depending on whether the user...

1 affected package

symfony

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
symfony Not affected Not affected Fixed Fixed
Show less packages

CVE-2020-15094

Medium priority
Ignored

In Symfony before versions 4.4.13 and 5.1.5, the CachingHttpClient class from the HttpClient Symfony component relies on the HttpCache class to handle requests. HttpCache uses internal headers like X-Body-Eval and X-Body-File to...

1 affected package

symfony

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
symfony Not affected Not affected Not affected
Show less packages

CVE-2020-5275

Medium priority
Ignored

In symfony/security-http before versions 4.4.7 and 5.0.7, when a `Firewall` checks access control rule, it iterate overs each rule's attributes and stops as soon as the accessDecisionManager decides to grant access on...

1 affected package

symfony

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
symfony Not affected Not affected Not affected
Show less packages

CVE-2020-5274

Medium priority
Ignored

In Symfony before versions 5.0.5 and 4.4.5, some properties of the Exception were not properly escaped when the `ErrorHandler` rendered it stacktrace. In addition, the stacktrace were displayed even in a non-debug configuration....

1 affected package

symfony

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
symfony Not affected Not affected Not affected
Show less packages

CVE-2020-5255

Medium priority
Ignored

In Symfony before versions 4.4.7 and 5.0.7, when a `Response` does not contain a `Content-Type` header, affected versions of Symfony can fallback to the format defined in the `Accept` header of the request, leading to a possible...

1 affected package

symfony

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
symfony Not affected Not affected Not affected
Show less packages

CVE-2019-18889

Medium priority
Vulnerable

An issue was discovered in Symfony 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4.3.7. Serializing certain cache adapter interfaces could result in remote code injection. This is related to symfony/cache.

1 affected package

symfony

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
symfony Not affected Not affected Not affected Not affected Vulnerable
Show less packages