cbcvebase.

Debian Symfony vulnerabilities

52 known vulnerabilities affecting debian/symfony.

Total CVEs
52
CISA KEV
0
Public exploits
3
Exploited in wild
0
Severity breakdown
CRITICAL6HIGH16MEDIUM20LOW9UNKNOWN1

Vulnerabilities

Page 2 of 3
CVE-2019-18887P3HIGHCVSS 8.1fixed in symfony 4.3.8+dfsg-1 (bookworm)2019
CVE-2019-18887 [HIGH] CVE-2019-18887: symfony - An issue was discovered in Symfony 2.8.0 through 2.8.50, 3.4.0 through 3.4.34, 4... An issue was discovered in Symfony 2.8.0 through 2.8.50, 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4.3.7. The UriSigner was subject to timing attacks. This is related to symfony/http-kernel. Scope: local bookworm: resolved (fixed in 4.3.8+dfsg-1) bullseye: resolved (fixed in 4.3.8+dfsg-1) forky: resolved (fixed in 4.3.8+dfsg-1) sid: resolved (fix
debian
CVE-2016-1902P3HIGHCVSS 7.5fixed in symfony 2.7.9+dfsg-1 (bookworm)2016
CVE-2016-1902 [HIGH] CVE-2016-1902: symfony - The nextBytes function in the SecureRandom class in Symfony before 2.3.37, 2.6.x... The nextBytes function in the SecureRandom class in Symfony before 2.3.37, 2.6.x before 2.6.13, and 2.7.x before 2.7.9 does not properly generate random numbers when used with PHP 5.x without the paragonie/random_compat library and the openssl_random_pseudo_bytes function fails, which makes it easier for attackers to defeat cryptographic protection mechanisms via unsp
debian
CVE-2008-7220P3LOWCVSS 7.5fixed in asterisk 1:1.6.2.0~rc3-1 (bullseye)2008
CVE-2008-7220 [HIGH] CVE-2008-7220: asterisk - Unspecified vulnerability in Prototype JavaScript framework (prototypejs) before... Unspecified vulnerability in Prototype JavaScript framework (prototypejs) before 1.6.0.2 allows attackers to make "cross-site ajax requests" via unknown vectors. Scope: local bullseye: resolved (fixed in 1:1.6.2.0~rc3-1) sid: resolved (fixed in 1:1.6.2.0~rc3-1)
debian
CVE-2015-2308P3MEDIUMCVSS 6.8fixed in symfony 2.3.21+dfsg-4 (bookworm)2015
CVE-2015-2308 [MEDIUM] CVE-2015-2308: symfony - Eval injection vulnerability in the HttpCache class in HttpKernel in Symfony 2.x... Eval injection vulnerability in the HttpCache class in HttpKernel in Symfony 2.x before 2.3.27, 2.4.x and 2.5.x before 2.5.11, and 2.6.x before 2.6.6 allows remote attackers to execute arbitrary PHP code via a language="php" attribute of a SCRIPT element. Scope: local bookworm: resolved (fixed in 2.3.21+dfsg-4) bullseye: resolved (fixed in 2.3.21+dfsg-4) forky: reso
debian
CVE-2015-8125P3HIGHCVSS 7.5fixed in symfony 2.7.7+dfsg-1 (bookworm)2015
CVE-2015-8125 [HIGH] CVE-2015-8125: symfony - Symfony 2.3.x before 2.3.35, 2.6.x before 2.6.12, and 2.7.x before 2.7.7 might a... Symfony 2.3.x before 2.3.35, 2.6.x before 2.6.12, and 2.7.x before 2.7.7 might allow remote attackers to have unspecified impact via a timing attack involving the (1) Symfony/Component/Security/Http/RememberMe/PersistentTokenBasedRememberMeServices or (2) Symfony/Component/Security/Http/Firewall/DigestAuthenticationListener class in the Symfony Security Component, or
debian
CVE-2016-4423P3HIGHCVSS 7.5fixed in symfony 2.8.6+dfsg-1 (bookworm)2016
CVE-2016-4423 [HIGH] CVE-2016-4423: symfony - The attemptAuthentication function in Component/Security/Http/Firewall/UsernameP... The attemptAuthentication function in Component/Security/Http/Firewall/UsernamePasswordFormAuthenticationListener.php in Symfony before 2.3.41, 2.7.x before 2.7.13, 2.8.x before 2.8.6, and 3.0.x before 3.0.6 does not limit the length of a username stored in a session, which allows remote attackers to cause a denial of service (session storage consumption) via a series
debian
CVE-2017-16790P3MEDIUMCVSS 6.5fixed in symfony 3.4.0+dfsg-1 (bookworm)2017
CVE-2017-16790 [MEDIUM] CVE-2017-16790: symfony - An issue was discovered in Symfony before 2.7.38, 2.8.31, 3.2.14, 3.3.13, 3.4-BE... An issue was discovered in Symfony before 2.7.38, 2.8.31, 3.2.14, 3.3.13, 3.4-BETA5, and 4.0-BETA5. When a form is submitted by the user, the request handler classes of the Form component merge POST data and uploaded files data into one array. This big array forms the data that are then bound to the form. At this stage there is no difference anymore between submit
debian
CVE-2021-41270P3MEDIUMCVSS 6.5fixed in symfony 4.4.19+dfsg-3 (bookworm)2021
CVE-2021-41270 [MEDIUM] CVE-2021-41270: symfony - Symfony/Serializer handles serializing and deserializing data structures for Sym... Symfony/Serializer handles serializing and deserializing data structures for Symfony, a PHP framework for web and console applications and a set of reusable PHP components. Symfony versions 4.1.0 before 4.4.35 and versions 5.0.0 before 5.3.12 are vulnerable to CSV injection, also known as formula injection. In Symfony 4.1, maintainers added the opt-in `csv_escape_
debian
CVE-2018-11406P3HIGHCVSS 8.8fixed in symfony 3.4.12+dfsg-1 (bookworm)2018
CVE-2018-11406 [HIGH] CVE-2018-11406: symfony - An issue was discovered in the Security component in Symfony 2.7.x before 2.7.48... An issue was discovered in the Security component in Symfony 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x before 4.0.11. By default, a user's session is invalidated when the user is logged out. This behavior can be disabled through the invalidate_session option. In this case, CSRF tokens were not erased during logout
debian
CVE-2018-14774P3HIGHCVSS 7.2fixed in symfony 3.4.14+dfsg-1 (bookworm)2018
CVE-2018-14774 [HIGH] CVE-2018-14774: symfony - An issue was discovered in HttpKernel in Symfony 2.7.0 through 2.7.48, 2.8.0 thr... An issue was discovered in HttpKernel in Symfony 2.7.0 through 2.7.48, 2.8.0 through 2.8.43, 3.3.0 through 3.3.17, 3.4.0 through 3.4.13, 4.0.0 through 4.0.13, and 4.1.0 through 4.1.2. When using HttpCache, the values of the X-Forwarded-Host headers are implicitly set as trusted while this should be forbidden, leading to potential host header injection. Scope: local
debian
CVE-2023-46733P3MEDIUMCVSS 6.5fixed in symfony 5.4.23+dfsg-1+deb12u1 (bookworm)2023
CVE-2023-46733 [MEDIUM] CVE-2023-46733: symfony - Symfony is a PHP framework for web and console applications and a set of reusabl... Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Starting in versions 5.4.21 and 6.2.7 and prior to versions 5.4.31 and 6.3.8, `SessionStrategyListener` does not migrate the session after every successful login. It does so only in case the logged in user changes by means of checking the user identifier. In some use
debian
CVE-2018-19789P4MEDIUMCVSS 5.3fixed in symfony 3.4.20+dfsg-1 (bookworm)2018
CVE-2018-19789 [MEDIUM] CVE-2018-19789: symfony - An issue was discovered in Symfony 2.7.x before 2.7.50, 2.8.x before 2.8.49, 3.x... An issue was discovered in Symfony 2.7.x before 2.7.50, 2.8.x before 2.8.49, 3.x before 3.4.20, 4.0.x before 4.0.15, 4.1.x before 4.1.9, and 4.2.x before 4.2.1. When using the scalar type hint `string` in a setter method (e.g. `setName(string $name)`) of a class that's the `data_class` of a form, and when a file upload is submitted to the corresponding field inste
debian
CVE-2017-18343P4LOWCVSS 6.1fixed in symfony 3.4.0+dfsg-1 (bookworm)2017
CVE-2017-18343 [MEDIUM] CVE-2017-18343: symfony - The debug handler in Symfony before v2.7.33, 2.8.x before v2.8.26, 3.x before v3... The debug handler in Symfony before v2.7.33, 2.8.x before v2.8.26, 3.x before v3.2.13, and 3.3.x before v3.3.6 has XSS via an array key during exception pretty printing in ExceptionHandler.php, as demonstrated by a /_debugbar/open?op=get URI. NOTE: the vendor's position is that this is not a vulnerability because the debug tools are not intended for production use
debian
CVE-2015-8124P4MEDIUMCVSS 6.8fixed in symfony 2.7.7+dfsg-1 (bookworm)2015
CVE-2015-8124 [MEDIUM] CVE-2015-8124: symfony - Session fixation vulnerability in the "Remember Me" login feature in Symfony 2.3... Session fixation vulnerability in the "Remember Me" login feature in Symfony 2.3.x before 2.3.35, 2.6.x before 2.6.12, and 2.7.x before 2.7.7 allows remote attackers to hijack web sessions via a session id. Scope: local bookworm: resolved (fixed in 2.7.7+dfsg-1) bullseye: resolved (fixed in 2.7.7+dfsg-1) forky: resolved (fixed in 2.7.7+dfsg-1) sid: resolved (fixed i
debian
CVE-2017-16653P4MEDIUMCVSS 5.9fixed in symfony 3.4.0+dfsg-1 (bookworm)2017
CVE-2017-16653 [MEDIUM] CVE-2017-16653: symfony - An issue was discovered in Symfony before 2.7.38, 2.8.31, 3.2.14, 3.3.13, 3.4-BE... An issue was discovered in Symfony before 2.7.38, 2.8.31, 3.2.14, 3.3.13, 3.4-BETA5, and 4.0-BETA5. The current implementation of CSRF protection in Symfony (Version >=2) does not use different tokens for HTTP and HTTPS; therefore the token is subject to MITM attacks on HTTP and can then be used in an HTTPS context to do CSRF attacks. Scope: local bookworm: resolv
debian
CVE-2021-21424P4MEDIUMCVSS 5.3fixed in symfony 4.4.19+dfsg-2 (bookworm)2021
CVE-2021-21424 [MEDIUM] CVE-2021-21424: symfony - Symfony is a PHP framework for web and console applications and a set of reusabl... Symfony is a PHP framework for web and console applications and a set of reusable PHP components. The ability to enumerate users was possible without relevant permissions due to different handling depending on whether the user existed or not when attempting to use the switch users functionality. We now ensure that 403s are returned whether the user exists or not i
debian
CVE-2019-18886P4MEDIUMCVSS 5.3fixed in symfony 4.3.8+dfsg-1 (bookworm)2019
CVE-2019-18886 [MEDIUM] CVE-2019-18886: symfony - An issue was discovered in Symfony 4.2.0 to 4.2.11 and 4.3.0 to 4.3.7. The abili... An issue was discovered in Symfony 4.2.0 to 4.2.11 and 4.3.0 to 4.3.7. The ability to enumerate users was possible due to different handling depending on whether the user existed when making unauthorized attempts to use the switch users functionality. This is related to symfony/security. Scope: local bookworm: resolved (fixed in 4.3.8+dfsg-1) bullseye: resolved (f
debian
CVE-2024-50345P4LOWCVSS 3.1fixed in symfony 5.4.23+dfsg-1+deb12u3 (bookworm)2024
CVE-2024-50345 [LOW] CVE-2024-50345: symfony - symfony/http-foundation is a module for the Symphony PHP framework which defines... symfony/http-foundation is a module for the Symphony PHP framework which defines an object-oriented layer for the HTTP specification. The `Request` class, does not parse URI with special characters the same way browsers do. As a result, an attacker can trick a validator relying on the `Request` class to redirect users to another domain. The `Request::create` methods
debian
CVE-2018-11386P4MEDIUMCVSS 5.9fixed in symfony 3.4.12+dfsg-1 (bookworm)2018
CVE-2018-11386 [MEDIUM] CVE-2018-11386: symfony - An issue was discovered in the HttpFoundation component in Symfony 2.7.x before ... An issue was discovered in the HttpFoundation component in Symfony 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x before 4.0.11. The PDOSessionHandler class allows storing sessions on a PDO connection. Under some configurations and with a well-crafted payload, it was possible to do a denial of service on a Symfony app
debian
CVE-2023-46734P4MEDIUMCVSS 6.1fixed in symfony 5.4.23+dfsg-1+deb12u1 (bookworm)2023
CVE-2023-46734 [MEDIUM] CVE-2023-46734: symfony - Symfony is a PHP framework for web and console applications and a set of reusabl... Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Starting in versions 2.0.0, 5.0.0, and 6.0.0 and prior to versions 4.4.51, 5.4.31, and 6.3.8, some Twig filters in CodeExtension use `is_safe=html` but don't actually ensure their input is safe. As of versions 4.4.51, 5.4.31, and 6.3.8, Symfony now escapes the output
debian