Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Require symfony/process ^6.4.14|^7.1.7 #902

Merged
merged 2 commits into from
Nov 6, 2024
Merged

Conversation

gndk
Copy link
Contributor

@gndk gndk commented Nov 6, 2024

symfony/process <6.4.14 and <7.1.7 contains CVE-2024-51736 which has been fixed in 6.4.14 and 7.1.7

https://symfony.com/blog/cve-2024-51736-command-execution-hijack-on-windows-with-process-class

gndk added 2 commits November 6, 2024 18:58
7.1.6 contains CVE-2024-51736 which has been fixed in 7.1.7
@gndk gndk changed the title Require symfony/process ^7.1.7 Require symfony/process ^6.4.14|^7.1.7 Nov 6, 2024
@gndk
Copy link
Contributor Author

gndk commented Nov 6, 2024

Separate PRs for the 7.x and 7.4.x branches, not sure if that was the correct thing to do

@Slamdunk Slamdunk merged commit 22e091c into paratestphp:7.x Nov 6, 2024
10 checks passed
@gndk gndk deleted the patch-1 branch November 6, 2024 18:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Development

Successfully merging this pull request may close these issues.

2 participants