Skip to content

Commit

Permalink
Merge pull request #734 from jderusse/security-advisories-2025-01
Browse files Browse the repository at this point in the history
Add advisories for Symfony Security Release 2024-01
  • Loading branch information
xabbuh authored Nov 6, 2024
2 parents af2a82a + a71c9a1 commit c0c781f
Show file tree
Hide file tree
Showing 12 changed files with 498 additions and 0 deletions.
47 changes: 47 additions & 0 deletions symfony/http-client/CVE-2024-50342.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,47 @@
title: "CVE-2024-50342: Internal address and port enumeration allowed by NoPrivateNetworkHttpClient"
link: https://symfony.com/cve-2024-50342
cve: CVE-2024-50342
branches:
4.3.x:
time: ~
versions: ['>=4.3.0', '<4.4.0']
4.4.x:
time: ~
versions: ['>=4.4.0', '<5.0.0']
5.0.x:
time: ~
versions: ['>=5.0.0', '<5.1.0']
5.1.x:
time: ~
versions: ['>=5.1.0', '<5.2.0']
5.2.x:
time: ~
versions: ['>=5.2.0', '<5.3.0']
5.3.x:
time: ~
versions: ['>=5.3.0', '<5.4.0']
5.4.x:
time: 2024-11-05 08:00:00
versions: ['>=5.4.0', '<5.4.46']
6.0.x:
time: ~
versions: ['>=6.0.0', '<6.1.0']
6.1.x:
time: ~
versions: ['>=6.1.0', '<6.2.0']
6.2.x:
time: ~
versions: ['>=6.2.0', '<6.3.0']
6.3.x:
time: ~
versions: ['>=6.3.0', '<6.4.0']
6.4.x:
time: 2024-11-05 08:00:00
versions: ['>=6.4.0', '<6.4.14']
7.0.x:
time: ~
versions: ['>=7.0.0', '<7.1.0']
7.1.x:
time: 2024-11-05 08:00:00
versions: ['>=7.1.0', '<7.1.7']
reference: composer://symfony/http-client
50 changes: 50 additions & 0 deletions symfony/http-foundation/CVE-2024-50345.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,50 @@
title: "CVE-2024-50345: Open redirect via browser-sanitized URLs"
link: https://symfony.com/cve-2024-50345
cve: CVE-2024-50345
branches:
2.x:
time: ~
versions: ['>=2.0.0', '<3.0.0']
3.x:
time: ~
versions: ['>=3.0.0', '<4.0.0']
4.x:
time: ~
versions: ['>=4.0.0', '<5.0.0']
5.0.x:
time: ~
versions: ['>=5.0.0', '<5.1.0']
5.1.x:
time: ~
versions: ['>=5.1.0', '<5.2.0']
5.2.x:
time: ~
versions: ['>=5.2.0', '<5.3.0']
5.3.x:
time: ~
versions: ['>=5.3.0', '<5.4.0']
5.4.x:
time: 2024-11-05 08:00:00
versions: ['>=5.4.0', '<5.4.46']
6.0.x:
time: ~
versions: ['>=6.0.0', '<6.1.0']
6.1.x:
time: ~
versions: ['>=6.1.0', '<6.2.0']
6.2.x:
time: ~
versions: ['>=6.2.0', '<6.3.0']
6.3.x:
time: ~
versions: ['>=6.3.0', '<6.4.0']
6.4.x:
time: 2024-11-05 08:00:00
versions: ['>=6.4.0', '<6.4.14']
7.0.x:
time: ~
versions: ['>=7.0.0', '<7.1.0']
7.1.x:
time: 2024-11-05 08:00:00
versions: ['>=7.1.0', '<7.1.7']
reference: composer://symfony/http-foundation
50 changes: 50 additions & 0 deletions symfony/process/CVE-2024-51736.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,50 @@
title: "CVE-2024-51736: Command execution hijack on Windows with Process class"
link: https://symfony.com/cve-2024-51736
cve: CVE-2024-51736
branches:
2.x:
time: ~
versions: ['>=2.0.0', '<3.0.0']
3.x:
time: ~
versions: ['>=3.0.0', '<4.0.0']
4.x:
time: ~
versions: ['>=4.0.0', '<5.0.0']
5.0.x:
time: ~
versions: ['>=5.0.0', '<5.1.0']
5.1.x:
time: ~
versions: ['>=5.1.0', '<5.2.0']
5.2.x:
time: ~
versions: ['>=5.2.0', '<5.3.0']
5.3.x:
time: ~
versions: ['>=5.3.0', '<5.4.0']
5.4.x:
time: 2024-11-05 08:00:00
versions: ['>=5.4.0', '<5.4.46']
6.0.x:
time: ~
versions: ['>=6.0.0', '<6.1.0']
6.1.x:
time: ~
versions: ['>=6.1.0', '<6.2.0']
6.2.x:
time: ~
versions: ['>=6.2.0', '<6.3.0']
6.3.x:
time: ~
versions: ['>=6.3.0', '<6.4.0']
6.4.x:
time: 2024-11-05 08:00:00
versions: ['>=6.4.0', '<6.4.14']
7.0.x:
time: ~
versions: ['>=7.0.0', '<7.1.0']
7.1.x:
time: 2024-11-05 08:00:00
versions: ['>=7.1.0', '<7.1.7']
reference: composer://symfony/process
32 changes: 32 additions & 0 deletions symfony/runtime/CVE-2024-50340.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,32 @@
title: "CVE-2024-50340: Ability to change environment from query"
link: https://symfony.com/cve-2024-50340
cve: CVE-2024-50340
branches:
5.3.x:
time: ~
versions: ['>=5.3.0', '<5.4.0']
5.4.x:
time: 2024-11-05 08:00:00
versions: ['>=5.4.0', '<5.4.46']
6.0.x:
time: ~
versions: ['>=6.0.0', '<6.1.0']
6.1.x:
time: ~
versions: ['>=6.1.0', '<6.2.0']
6.2.x:
time: ~
versions: ['>=6.2.0', '<6.3.0']
6.3.x:
time: ~
versions: ['>=6.3.0', '<6.4.0']
6.4.x:
time: 2024-11-05 08:00:00
versions: ['>=6.4.0', '<6.4.14']
7.0.x:
time: ~
versions: ['>=7.0.0', '<7.1.0']
7.1.x:
time: 2024-11-05 08:00:00
versions: ['>=7.1.0', '<7.1.7']
reference: composer://symfony/runtime
20 changes: 20 additions & 0 deletions symfony/security-bundle/CVE-2024-50341.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,20 @@
title: "CVE-2024-50341: Security::login does not take into account custom user_checker"
link: https://symfony.com/cve-2024-50341
cve: CVE-2024-50341
branches:
6.2.x:
time: ~
versions: ['>=6.2.0', '<6.3.0']
6.3.x:
time: ~
versions: ['>=6.3.0', '<6.4.0']
6.4.x:
time: 2024-07-17 08:00:00
versions: ['>=6.4.0', '<6.4.10']
7.0.x:
time: 2024-07-17 08:00:00
versions: ['>=7.0.0', '<7.0.10']
7.1.x:
time: 2024-07-17 08:00:00
versions: ['>=7.1.0', '<7.1.3']
reference: composer://symfony/security-bundle
32 changes: 32 additions & 0 deletions symfony/symfony/CVE-2024-50340.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,32 @@
title: "CVE-2024-50340: Ability to change environment from query"
link: https://symfony.com/cve-2024-50340
cve: CVE-2024-50340
branches:
5.3.x:
time: ~
versions: ['>=5.3.0', '<5.4.0']
5.4.x:
time: 2024-11-05 08:00:00
versions: ['>=5.4.0', '<5.4.46']
6.0.x:
time: ~
versions: ['>=6.0.0', '<6.1.0']
6.1.x:
time: ~
versions: ['>=6.1.0', '<6.2.0']
6.2.x:
time: ~
versions: ['>=6.2.0', '<6.3.0']
6.3.x:
time: ~
versions: ['>=6.3.0', '<6.4.0']
6.4.x:
time: 2024-11-05 08:00:00
versions: ['>=6.4.0', '<6.4.14']
7.0.x:
time: ~
versions: ['>=7.0.0', '<7.1.0']
7.1.x:
time: 2024-11-05 08:00:00
versions: ['>=7.1.0', '<7.1.7']
reference: composer://symfony/symfony
20 changes: 20 additions & 0 deletions symfony/symfony/CVE-2024-50341.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,20 @@
title: "CVE-2024-50341: Security::login does not take into account custom user_checker"
link: https://symfony.com/cve-2024-50341
cve: CVE-2024-50341
branches:
6.2.x:
time: ~
versions: ['>=6.2.0', '<6.3.0']
6.3.x:
time: ~
versions: ['>=6.3.0', '<6.4.0']
6.4.x:
time: 2024-07-17 08:00:00
versions: ['>=6.4.0', '<6.4.10']
7.0.x:
time: 2024-07-17 08:00:00
versions: ['>=7.0.0', '<7.0.10']
7.1.x:
time: 2024-07-17 08:00:00
versions: ['>=7.1.0', '<7.1.3']
reference: composer://symfony/symfony
47 changes: 47 additions & 0 deletions symfony/symfony/CVE-2024-50342.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,47 @@
title: "CVE-2024-50342: Internal address and port enumeration allowed by NoPrivateNetworkHttpClient"
link: https://symfony.com/cve-2024-50342
cve: CVE-2024-50342
branches:
4.3.x:
time: ~
versions: ['>=4.3.0', '<4.4.0']
4.4.x:
time: ~
versions: ['>=4.4.0', '<5.0.0']
5.0.x:
time: ~
versions: ['>=5.0.0', '<5.1.0']
5.1.x:
time: ~
versions: ['>=5.1.0', '<5.2.0']
5.2.x:
time: ~
versions: ['>=5.2.0', '<5.3.0']
5.3.x:
time: ~
versions: ['>=5.3.0', '<5.4.0']
5.4.x:
time: 2024-11-05 08:00:00
versions: ['>=5.4.0', '<5.4.46']
6.0.x:
time: ~
versions: ['>=6.0.0', '<6.1.0']
6.1.x:
time: ~
versions: ['>=6.1.0', '<6.2.0']
6.2.x:
time: ~
versions: ['>=6.2.0', '<6.3.0']
6.3.x:
time: ~
versions: ['>=6.3.0', '<6.4.0']
6.4.x:
time: 2024-11-05 08:00:00
versions: ['>=6.4.0', '<6.4.14']
7.0.x:
time: ~
versions: ['>=7.0.0', '<7.1.0']
7.1.x:
time: 2024-11-05 08:00:00
versions: ['>=7.1.0', '<7.1.7']
reference: composer://symfony/symfony
50 changes: 50 additions & 0 deletions symfony/symfony/CVE-2024-50343.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,50 @@
title: "CVE-2024-50343: Incorrect response from Validator when input ends with `\n`"
link: https://symfony.com/cve-2024-50343
cve: CVE-2024-50343
branches:
2.x:
time: ~
versions: ['>=2.0.0', '<3.0.0']
3.x:
time: ~
versions: ['>=3.0.0', '<4.0.0']
4.x:
time: ~
versions: ['>=4.0.0', '<5.0.0']
5.0.x:
time: ~
versions: ['>=5.0.0', '<5.1.0']
5.1.x:
time: ~
versions: ['>=5.1.0', '<5.2.0']
5.2.x:
time: ~
versions: ['>=5.2.0', '<5.3.0']
5.3.x:
time: ~
versions: ['>=5.3.0', '<5.4.0']
5.4.x:
time: 2024-08-30 08:00:00
versions: ['>=5.4.0', '<5.4.43']
6.0.x:
time: ~
versions: ['>=6.0.0', '<6.1.0']
6.1.x:
time: ~
versions: ['>=6.1.0', '<6.2.0']
6.2.x:
time: ~
versions: ['>=6.2.0', '<6.3.0']
6.3.x:
time: ~
versions: ['>=6.3.0', '<6.4.0']
6.4.x:
time: 2024-08-30 08:00:00
versions: ['>=6.4.0', '<6.4.11']
7.0.x:
time: ~
versions: ['>=7.0.0', '<7.1.0']
7.1.x:
time: 2024-08-30 08:00:00
versions: ['>=7.1.0', '<7.1.4']
reference: composer://symfony/symfony
Loading

0 comments on commit c0c781f

Please sign in to comment.