Search CVE reports


Toggle filters

61 – 70 of 84 results


CVE-2018-19790

Medium priority
Vulnerable

An open redirect was discovered in Symfony 2.7.x before 2.7.50, 2.8.x before 2.8.49, 3.x before 3.4.20, 4.0.x before 4.0.15, 4.1.x before 4.1.9 and 4.2.x before 4.2.1. By using backslashes in the `_failure_path` input field of...

1 affected package

symfony

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
symfony Not affected Not affected Not affected Not affected Vulnerable
Show less packages

CVE-2018-19789

Medium priority
Vulnerable

An issue was discovered in Symfony 2.7.x before 2.7.50, 2.8.x before 2.8.49, 3.x before 3.4.20, 4.0.x before 4.0.15, 4.1.x before 4.1.9, and 4.2.x before 4.2.1. When using the scalar type hint `string` in a setter method (e.g....

1 affected package

symfony

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
symfony Not affected Not affected Not affected Not affected Vulnerable
Show less packages

CVE-2017-16790

Medium priority
Not affected

An issue was discovered in Symfony before 2.7.38, 2.8.31, 3.2.14, 3.3.13, 3.4-BETA5, and 4.0-BETA5. When a form is submitted by the user, the request handler classes of the Form component merge POST data and uploaded files data...

1 affected package

symfony

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
symfony Not affected Not affected Not affected Not affected Not affected
Show less packages

CVE-2017-16654

Medium priority
Not affected

An issue was discovered in Symfony before 2.7.38, 2.8.31, 3.2.14, 3.3.13, 3.4-BETA5, and 4.0-BETA5. The Intl component includes various bundle readers that are used to read resource bundles from the local filesystem. The read()...

1 affected package

symfony

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
symfony Not affected Not affected Not affected Not affected Not affected
Show less packages

CVE-2017-16653

Medium priority
Not affected

An issue was discovered in Symfony before 2.7.38, 2.8.31, 3.2.14, 3.3.13, 3.4-BETA5, and 4.0-BETA5. The current implementation of CSRF protection in Symfony (Version >=2) does not use different tokens for HTTP and HTTPS; therefore...

1 affected package

symfony

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
symfony Not affected Not affected Not affected Not affected Not affected
Show less packages

CVE-2018-14774

Medium priority
Vulnerable

An issue was discovered in HttpKernel in Symfony 2.7.0 through 2.7.48, 2.8.0 through 2.8.43, 3.3.0 through 3.3.17, 3.4.0 through 3.4.13, 4.0.0 through 4.0.13, and 4.1.0 through 4.1.2. When using HttpCache, the values of the...

1 affected package

symfony

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
symfony Not affected Not affected Not affected Not affected Vulnerable
Show less packages

CVE-2018-14773

Medium priority
Vulnerable

An issue was discovered in Http Foundation in Symfony 2.7.0 through 2.7.48, 2.8.0 through 2.8.43, 3.3.0 through 3.3.17, 3.4.0 through 3.4.13, 4.0.0 through 4.0.13, and 4.1.0 through 4.1.2. It arises from support for a (legacy) IIS...

1 affected package

symfony

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
symfony Not affected Not affected Not affected Not affected Vulnerable
Show less packages

CVE-2017-18343

Medium priority
Ignored

The debug handler in Symfony before v2.7.33, 2.8.x before v2.8.26, 3.x before v3.2.13, and 3.3.x before v3.3.6 has XSS via an array key during exception pretty printing in ExceptionHandler.php, as demonstrated by...

1 affected package

symfony

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
symfony Not affected Not affected Not affected Not affected
Show less packages

CVE-2018-12040

Negligible priority
Ignored

Reflected Cross-site scripting (XSS) vulnerability in the web profiler in SensioLabs Symfony 3.3.6 allows remote attackers to inject arbitrary web script or HTML via the "file" parameter, aka an _profiler/open?file= URI. NOTE: The...

1 affected package

symfony

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
symfony Not affected Not affected Not affected Not affected
Show less packages

CVE-2018-11408

Low priority
Vulnerable

The security handlers in the Security component in Symfony in 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x before 4.0.11 have an Open redirect vulnerability when security.http_utils...

1 affected package

symfony

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
symfony Not affected Not affected Not affected Not affected Vulnerable
Show less packages