Vulnerabilities > Sensiolabs

DATE CVE VULNERABILITY TITLE RISK
2023-02-03 CVE-2022-24894 Improper Authorization vulnerability in Sensiolabs Symfony
Symfony is a PHP framework for web and console applications and a set of reusable PHP components.
network
low complexity
sensiolabs CWE-285
8.8
2023-02-03 CVE-2022-24895 Session Fixation vulnerability in Sensiolabs Symfony
Symfony is a PHP framework for web and console applications and a set of reusable PHP components.
network
low complexity
sensiolabs CWE-384
8.8
2022-02-01 CVE-2022-23601 Cross-Site Request Forgery (CSRF) vulnerability in Sensiolabs Symfony
Symfony is a PHP framework for web and console applications and a set of reusable PHP components.
6.8
2021-11-24 CVE-2021-41267 HTTP Request Smuggling vulnerability in Sensiolabs Symfony
Symfony/Http-Kernel is the HTTP kernel component for Symfony, a PHP framework for web and console applications and a set of reusable PHP components.
4.3
2021-11-24 CVE-2021-41268 Session Fixation vulnerability in Sensiolabs Symfony
Symfony/SecurityBundle is the security system for Symfony, a PHP framework for web and console applications and a set of reusable PHP components.
network
low complexity
sensiolabs CWE-384
6.5
2021-11-24 CVE-2021-41270 Improper Neutralization of Formula Elements in a CSV File vulnerability in multiple products
Symfony/Serializer handles serializing and deserializing data structures for Symfony, a PHP framework for web and console applications and a set of reusable PHP components.
network
low complexity
sensiolabs fedoraproject CWE-1236
4.0
2021-06-17 CVE-2021-32693 Improper Authentication vulnerability in Sensiolabs Symfony 5.3.0
Symfony is a PHP framework for web and console applications and a set of reusable PHP components.
network
low complexity
sensiolabs CWE-287
6.5
2021-05-13 CVE-2021-21424 Information Exposure Through Discrepancy vulnerability in multiple products
Symfony is a PHP framework for web and console applications and a set of reusable PHP components.
network
low complexity
sensiolabs fedoraproject CWE-203
5.3
2020-09-02 CVE-2020-15094 Improper Cross-boundary Removal of Sensitive Data vulnerability in multiple products
In Symfony before versions 4.4.13 and 5.1.5, the CachingHttpClient class from the HttpClient Symfony component relies on the HttpCache class to handle requests.
network
low complexity
sensiolabs fedoraproject CWE-212
8.8
2020-03-30 CVE-2020-5275 Incorrect Authorization vulnerability in Sensiolabs Symfony
In symfony/security-http before versions 4.4.7 and 5.0.7, when a `Firewall` checks access control rule, it iterate overs each rule's attributes and stops as soon as the accessDecisionManager decides to grant access on the attribute, preventing the check of next attributes that should have been take into account in an unanimous strategy.
network
low complexity
sensiolabs CWE-863
5.5