An open API service providing security vulnerability metadata for many open source software ecosystems.

packagist

symfony/symfony

packagist · The Symfony PHP framework · Repository · Package

Moderate Security Advisories for symfony/symfony in packagist Clear Filters

Moderate
11 months ago

Symfony allows changing the environment through a query GSA_kwCzR0hTQS14OHZwLWdmNHEtbXc1as4ABBBb

packagist symfony/symfony, symfony/runtime
Moderate
over 1 year ago

Symfony has unsafe methods in the Request class GSA_kwCzR0hTQS1wNjg0LWY3ZmgtanYyas4AA8jb

packagist symfony/symfony, symfony/http-foundation
Moderate
over 1 year ago

Symfony has a security issue when parsing the Authorization header GSA_kwCzR0hTQS1oN3YyLTJxd2ctaDgyOc4AA8ja

packagist symfony/symfony, symfony/http-foundation
Moderate
over 1 year ago

Symfony2 security issue when the trust proxy mode is enabled GSA_kwCzR0hTQS12Zm02LXIyZ2MtcHd3d84AA8jY

packagist symfony/symfony, symfony/http-foundation
Moderate
almost 2 years ago

Symfony potential Cross-site Scripting in WebhookController GSA_kwCzR0hTQS03MngyLTVjODUtNndtcs4AA3Cz

packagist symfony/symfony, symfony/webhook
Moderate
almost 2 years ago

Symfony possible session fixation vulnerability GSA_kwCzR0hTQS1tMndqLXI2ZzMtZnhmeM4AA3Cx

packagist symfony/symfony, symfony/security-http
Moderate
over 2 years ago

Symfony storing cookie headers in HttpCache GSA_kwCzR0hTQS1oN3ZmLTV3cnYtOWZods4AAxVO

packagist symfony/symfony, symfony/http-kernel
Moderate
over 2 years ago

Symfony vulnerable to Session Fixation of CSRF tokens GSA_kwCzR0hTQS0zZ3YyLTI5cWMtdjY3bc4AAxVN

packagist symfony/symfony, symfony/security-bundle
Moderate
over 3 years ago

Symfony Allows URI Restrictions Bypass Via Double-Encoded String GSA_kwCzR0hTQS04M2MzLXF4MjctMnJ3cs4AAfXs

packagist symfony/symfony, symfony/security, symfony/routing, symfony/http-foundation
Moderate
over 3 years ago

Symfony Denial of Service Via Long Password Hashing GSA_kwCzR0hTQS1jcjQ5LWZ4MnYtOXA1N84AAd7g

packagist symfony/security, symfony/polyfill, symfony/symfony
Moderate
over 3 years ago

Symfony Vulnerable to PHP Eval Injection GSA_kwCzR0hTQS01YzU4LXc5eGMtcWNqOc4AAc0N

packagist symfony/http-kernel, symfony/symfony
Moderate
over 3 years ago

Symfony Incorrect Access Control GSA_kwCzR0hTQS1xbXF3LW1wcXAtbXI1NM4AAcRE

packagist symfony/http-kernel, symfony/symfony
Moderate
over 3 years ago

Symfony SSRF Vulnerability via Form Component GSA_kwCzR0hTQS1jcXFoLTk0cjYtd2pyZ84AAV2m

packagist symfony/symfony, symfony/form
Moderate
over 3 years ago

Symfony Open Redirect GSA_kwCzR0hTQS04OXIyLTVnMzQtMmc0N84AATfR

packagist symfony/symfony, symfony/security, symfony/security-http
Moderate
over 3 years ago

Symfony CSRF Vulnerability GSA_kwCzR0hTQS05Mng2LWgyZ3ItOGd4cc4AASJF

packagist symfony/symfony, symfony/security, symfony/security-csrf
Moderate
almost 4 years ago

CSV Injection in symfony/serializer GSA_kwCzR0hTQS0yeGhnLXcyZzUtdzk1eM0YGA

packagist symfony/symfony
Moderate
over 4 years ago

Prevent user enumeration using Guard or the new Authenticator-based Security MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTVwdjgtcHB2ai00aDY4

packagist symfony/symfony, symfony/security, symfony/security-http, symfony/maker-bundle, lexik/jwt-authentication-bundle, symfony/security-core, symfony/security-guard