-
Notifications
You must be signed in to change notification settings - Fork 306
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Merge pull request #734 from jderusse/security-advisories-2025-01
Add advisories for Symfony Security Release 2024-01
- Loading branch information
Showing
12 changed files
with
498 additions
and
0 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,47 @@ | ||
title: "CVE-2024-50342: Internal address and port enumeration allowed by NoPrivateNetworkHttpClient" | ||
link: https://symfony.com/cve-2024-50342 | ||
cve: CVE-2024-50342 | ||
branches: | ||
4.3.x: | ||
time: ~ | ||
versions: ['>=4.3.0', '<4.4.0'] | ||
4.4.x: | ||
time: ~ | ||
versions: ['>=4.4.0', '<5.0.0'] | ||
5.0.x: | ||
time: ~ | ||
versions: ['>=5.0.0', '<5.1.0'] | ||
5.1.x: | ||
time: ~ | ||
versions: ['>=5.1.0', '<5.2.0'] | ||
5.2.x: | ||
time: ~ | ||
versions: ['>=5.2.0', '<5.3.0'] | ||
5.3.x: | ||
time: ~ | ||
versions: ['>=5.3.0', '<5.4.0'] | ||
5.4.x: | ||
time: 2024-11-05 08:00:00 | ||
versions: ['>=5.4.0', '<5.4.46'] | ||
6.0.x: | ||
time: ~ | ||
versions: ['>=6.0.0', '<6.1.0'] | ||
6.1.x: | ||
time: ~ | ||
versions: ['>=6.1.0', '<6.2.0'] | ||
6.2.x: | ||
time: ~ | ||
versions: ['>=6.2.0', '<6.3.0'] | ||
6.3.x: | ||
time: ~ | ||
versions: ['>=6.3.0', '<6.4.0'] | ||
6.4.x: | ||
time: 2024-11-05 08:00:00 | ||
versions: ['>=6.4.0', '<6.4.14'] | ||
7.0.x: | ||
time: ~ | ||
versions: ['>=7.0.0', '<7.1.0'] | ||
7.1.x: | ||
time: 2024-11-05 08:00:00 | ||
versions: ['>=7.1.0', '<7.1.7'] | ||
reference: composer://symfony/http-client |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,50 @@ | ||
title: "CVE-2024-50345: Open redirect via browser-sanitized URLs" | ||
link: https://symfony.com/cve-2024-50345 | ||
cve: CVE-2024-50345 | ||
branches: | ||
2.x: | ||
time: ~ | ||
versions: ['>=2.0.0', '<3.0.0'] | ||
3.x: | ||
time: ~ | ||
versions: ['>=3.0.0', '<4.0.0'] | ||
4.x: | ||
time: ~ | ||
versions: ['>=4.0.0', '<5.0.0'] | ||
5.0.x: | ||
time: ~ | ||
versions: ['>=5.0.0', '<5.1.0'] | ||
5.1.x: | ||
time: ~ | ||
versions: ['>=5.1.0', '<5.2.0'] | ||
5.2.x: | ||
time: ~ | ||
versions: ['>=5.2.0', '<5.3.0'] | ||
5.3.x: | ||
time: ~ | ||
versions: ['>=5.3.0', '<5.4.0'] | ||
5.4.x: | ||
time: 2024-11-05 08:00:00 | ||
versions: ['>=5.4.0', '<5.4.46'] | ||
6.0.x: | ||
time: ~ | ||
versions: ['>=6.0.0', '<6.1.0'] | ||
6.1.x: | ||
time: ~ | ||
versions: ['>=6.1.0', '<6.2.0'] | ||
6.2.x: | ||
time: ~ | ||
versions: ['>=6.2.0', '<6.3.0'] | ||
6.3.x: | ||
time: ~ | ||
versions: ['>=6.3.0', '<6.4.0'] | ||
6.4.x: | ||
time: 2024-11-05 08:00:00 | ||
versions: ['>=6.4.0', '<6.4.14'] | ||
7.0.x: | ||
time: ~ | ||
versions: ['>=7.0.0', '<7.1.0'] | ||
7.1.x: | ||
time: 2024-11-05 08:00:00 | ||
versions: ['>=7.1.0', '<7.1.7'] | ||
reference: composer://symfony/http-foundation |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,50 @@ | ||
title: "CVE-2024-51736: Command execution hijack on Windows with Process class" | ||
link: https://symfony.com/cve-2024-51736 | ||
cve: CVE-2024-51736 | ||
branches: | ||
2.x: | ||
time: ~ | ||
versions: ['>=2.0.0', '<3.0.0'] | ||
3.x: | ||
time: ~ | ||
versions: ['>=3.0.0', '<4.0.0'] | ||
4.x: | ||
time: ~ | ||
versions: ['>=4.0.0', '<5.0.0'] | ||
5.0.x: | ||
time: ~ | ||
versions: ['>=5.0.0', '<5.1.0'] | ||
5.1.x: | ||
time: ~ | ||
versions: ['>=5.1.0', '<5.2.0'] | ||
5.2.x: | ||
time: ~ | ||
versions: ['>=5.2.0', '<5.3.0'] | ||
5.3.x: | ||
time: ~ | ||
versions: ['>=5.3.0', '<5.4.0'] | ||
5.4.x: | ||
time: 2024-11-05 08:00:00 | ||
versions: ['>=5.4.0', '<5.4.46'] | ||
6.0.x: | ||
time: ~ | ||
versions: ['>=6.0.0', '<6.1.0'] | ||
6.1.x: | ||
time: ~ | ||
versions: ['>=6.1.0', '<6.2.0'] | ||
6.2.x: | ||
time: ~ | ||
versions: ['>=6.2.0', '<6.3.0'] | ||
6.3.x: | ||
time: ~ | ||
versions: ['>=6.3.0', '<6.4.0'] | ||
6.4.x: | ||
time: 2024-11-05 08:00:00 | ||
versions: ['>=6.4.0', '<6.4.14'] | ||
7.0.x: | ||
time: ~ | ||
versions: ['>=7.0.0', '<7.1.0'] | ||
7.1.x: | ||
time: 2024-11-05 08:00:00 | ||
versions: ['>=7.1.0', '<7.1.7'] | ||
reference: composer://symfony/process |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,32 @@ | ||
title: "CVE-2024-50340: Ability to change environment from query" | ||
link: https://symfony.com/cve-2024-50340 | ||
cve: CVE-2024-50340 | ||
branches: | ||
5.3.x: | ||
time: ~ | ||
versions: ['>=5.3.0', '<5.4.0'] | ||
5.4.x: | ||
time: 2024-11-05 08:00:00 | ||
versions: ['>=5.4.0', '<5.4.46'] | ||
6.0.x: | ||
time: ~ | ||
versions: ['>=6.0.0', '<6.1.0'] | ||
6.1.x: | ||
time: ~ | ||
versions: ['>=6.1.0', '<6.2.0'] | ||
6.2.x: | ||
time: ~ | ||
versions: ['>=6.2.0', '<6.3.0'] | ||
6.3.x: | ||
time: ~ | ||
versions: ['>=6.3.0', '<6.4.0'] | ||
6.4.x: | ||
time: 2024-11-05 08:00:00 | ||
versions: ['>=6.4.0', '<6.4.14'] | ||
7.0.x: | ||
time: ~ | ||
versions: ['>=7.0.0', '<7.1.0'] | ||
7.1.x: | ||
time: 2024-11-05 08:00:00 | ||
versions: ['>=7.1.0', '<7.1.7'] | ||
reference: composer://symfony/runtime |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,20 @@ | ||
title: "CVE-2024-50341: Security::login does not take into account custom user_checker" | ||
link: https://symfony.com/cve-2024-50341 | ||
cve: CVE-2024-50341 | ||
branches: | ||
6.2.x: | ||
time: ~ | ||
versions: ['>=6.2.0', '<6.3.0'] | ||
6.3.x: | ||
time: ~ | ||
versions: ['>=6.3.0', '<6.4.0'] | ||
6.4.x: | ||
time: 2024-07-17 08:00:00 | ||
versions: ['>=6.4.0', '<6.4.10'] | ||
7.0.x: | ||
time: 2024-07-17 08:00:00 | ||
versions: ['>=7.0.0', '<7.0.10'] | ||
7.1.x: | ||
time: 2024-07-17 08:00:00 | ||
versions: ['>=7.1.0', '<7.1.3'] | ||
reference: composer://symfony/security-bundle |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,32 @@ | ||
title: "CVE-2024-50340: Ability to change environment from query" | ||
link: https://symfony.com/cve-2024-50340 | ||
cve: CVE-2024-50340 | ||
branches: | ||
5.3.x: | ||
time: ~ | ||
versions: ['>=5.3.0', '<5.4.0'] | ||
5.4.x: | ||
time: 2024-11-05 08:00:00 | ||
versions: ['>=5.4.0', '<5.4.46'] | ||
6.0.x: | ||
time: ~ | ||
versions: ['>=6.0.0', '<6.1.0'] | ||
6.1.x: | ||
time: ~ | ||
versions: ['>=6.1.0', '<6.2.0'] | ||
6.2.x: | ||
time: ~ | ||
versions: ['>=6.2.0', '<6.3.0'] | ||
6.3.x: | ||
time: ~ | ||
versions: ['>=6.3.0', '<6.4.0'] | ||
6.4.x: | ||
time: 2024-11-05 08:00:00 | ||
versions: ['>=6.4.0', '<6.4.14'] | ||
7.0.x: | ||
time: ~ | ||
versions: ['>=7.0.0', '<7.1.0'] | ||
7.1.x: | ||
time: 2024-11-05 08:00:00 | ||
versions: ['>=7.1.0', '<7.1.7'] | ||
reference: composer://symfony/symfony |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,20 @@ | ||
title: "CVE-2024-50341: Security::login does not take into account custom user_checker" | ||
link: https://symfony.com/cve-2024-50341 | ||
cve: CVE-2024-50341 | ||
branches: | ||
6.2.x: | ||
time: ~ | ||
versions: ['>=6.2.0', '<6.3.0'] | ||
6.3.x: | ||
time: ~ | ||
versions: ['>=6.3.0', '<6.4.0'] | ||
6.4.x: | ||
time: 2024-07-17 08:00:00 | ||
versions: ['>=6.4.0', '<6.4.10'] | ||
7.0.x: | ||
time: 2024-07-17 08:00:00 | ||
versions: ['>=7.0.0', '<7.0.10'] | ||
7.1.x: | ||
time: 2024-07-17 08:00:00 | ||
versions: ['>=7.1.0', '<7.1.3'] | ||
reference: composer://symfony/symfony |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,47 @@ | ||
title: "CVE-2024-50342: Internal address and port enumeration allowed by NoPrivateNetworkHttpClient" | ||
link: https://symfony.com/cve-2024-50342 | ||
cve: CVE-2024-50342 | ||
branches: | ||
4.3.x: | ||
time: ~ | ||
versions: ['>=4.3.0', '<4.4.0'] | ||
4.4.x: | ||
time: ~ | ||
versions: ['>=4.4.0', '<5.0.0'] | ||
5.0.x: | ||
time: ~ | ||
versions: ['>=5.0.0', '<5.1.0'] | ||
5.1.x: | ||
time: ~ | ||
versions: ['>=5.1.0', '<5.2.0'] | ||
5.2.x: | ||
time: ~ | ||
versions: ['>=5.2.0', '<5.3.0'] | ||
5.3.x: | ||
time: ~ | ||
versions: ['>=5.3.0', '<5.4.0'] | ||
5.4.x: | ||
time: 2024-11-05 08:00:00 | ||
versions: ['>=5.4.0', '<5.4.46'] | ||
6.0.x: | ||
time: ~ | ||
versions: ['>=6.0.0', '<6.1.0'] | ||
6.1.x: | ||
time: ~ | ||
versions: ['>=6.1.0', '<6.2.0'] | ||
6.2.x: | ||
time: ~ | ||
versions: ['>=6.2.0', '<6.3.0'] | ||
6.3.x: | ||
time: ~ | ||
versions: ['>=6.3.0', '<6.4.0'] | ||
6.4.x: | ||
time: 2024-11-05 08:00:00 | ||
versions: ['>=6.4.0', '<6.4.14'] | ||
7.0.x: | ||
time: ~ | ||
versions: ['>=7.0.0', '<7.1.0'] | ||
7.1.x: | ||
time: 2024-11-05 08:00:00 | ||
versions: ['>=7.1.0', '<7.1.7'] | ||
reference: composer://symfony/symfony |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,50 @@ | ||
title: "CVE-2024-50343: Incorrect response from Validator when input ends with `\n`" | ||
link: https://symfony.com/cve-2024-50343 | ||
cve: CVE-2024-50343 | ||
branches: | ||
2.x: | ||
time: ~ | ||
versions: ['>=2.0.0', '<3.0.0'] | ||
3.x: | ||
time: ~ | ||
versions: ['>=3.0.0', '<4.0.0'] | ||
4.x: | ||
time: ~ | ||
versions: ['>=4.0.0', '<5.0.0'] | ||
5.0.x: | ||
time: ~ | ||
versions: ['>=5.0.0', '<5.1.0'] | ||
5.1.x: | ||
time: ~ | ||
versions: ['>=5.1.0', '<5.2.0'] | ||
5.2.x: | ||
time: ~ | ||
versions: ['>=5.2.0', '<5.3.0'] | ||
5.3.x: | ||
time: ~ | ||
versions: ['>=5.3.0', '<5.4.0'] | ||
5.4.x: | ||
time: 2024-08-30 08:00:00 | ||
versions: ['>=5.4.0', '<5.4.43'] | ||
6.0.x: | ||
time: ~ | ||
versions: ['>=6.0.0', '<6.1.0'] | ||
6.1.x: | ||
time: ~ | ||
versions: ['>=6.1.0', '<6.2.0'] | ||
6.2.x: | ||
time: ~ | ||
versions: ['>=6.2.0', '<6.3.0'] | ||
6.3.x: | ||
time: ~ | ||
versions: ['>=6.3.0', '<6.4.0'] | ||
6.4.x: | ||
time: 2024-08-30 08:00:00 | ||
versions: ['>=6.4.0', '<6.4.11'] | ||
7.0.x: | ||
time: ~ | ||
versions: ['>=7.0.0', '<7.1.0'] | ||
7.1.x: | ||
time: 2024-08-30 08:00:00 | ||
versions: ['>=7.1.0', '<7.1.4'] | ||
reference: composer://symfony/symfony |
Oops, something went wrong.