Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWc5OTYtcTVyOC13N2cy

Symfony Cross-site Scripting (XSS) vulnerability

In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, validation messages are not escaped, which can lead to XSS when user input is included. This is related to symfony/framework-bundle.

Permalink: https://github.com/advisories/GHSA-g996-q5r8-w7g2
JSON: https://advisories.ecosyste.ms/api/v1/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWc5OTYtcTVyOC13N2cy
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Moderate
Classification: General
Published: about 4 years ago
Updated: 2 months ago


CVSS Score: 5.4
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Identifiers: GHSA-g996-q5r8-w7g2, CVE-2019-10909
References:

Affected Packages

packagist:drupal/core
Versions: >= 8.6.0, < 8.6.15, < 8.5.15
Fixed in: 8.6.15, 8.5.15
packagist:symfony/symfony
Versions: >= 4.2.0, < 4.2.7, >= 4.0.0, < 4.1.12, >= 3.0.0, < 3.4.26, >= 2.8.0, < 2.8.50, >= 2.7.0, < 2.7.51
Fixed in: 4.2.7, 4.1.12, 3.4.26, 2.8.50, 2.7.51
packagist:symfony/framework-bundle
Versions: >= 4.2.0, < 4.2.7, >= 4.0.0, < 4.1.12, >= 3.0.0, < 3.4.26, >= 2.8.0, < 2.8.50, >= 2.7.0, < 2.7.51
Fixed in: 4.2.7, 4.1.12, 3.4.26, 2.8.50, 2.7.51