Vulnerabilities > Sensiolabs > Symfony > 4.4.0
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-11-10 | CVE-2023-46734 | Cross-site Scripting vulnerability in Sensiolabs Symfony Symfony is a PHP framework for web and console applications and a set of reusable PHP components. | 6.1 |
2023-02-03 | CVE-2022-24894 | Improper Authorization vulnerability in Sensiolabs Symfony Symfony is a PHP framework for web and console applications and a set of reusable PHP components. | 8.8 |
2023-02-03 | CVE-2022-24895 | Session Fixation vulnerability in Sensiolabs Symfony Symfony is a PHP framework for web and console applications and a set of reusable PHP components. | 8.8 |
2022-02-01 | CVE-2022-23601 | Cross-Site Request Forgery (CSRF) vulnerability in Sensiolabs Symfony Symfony is a PHP framework for web and console applications and a set of reusable PHP components. | 6.8 |
2021-11-24 | CVE-2021-41270 | Improper Neutralization of Formula Elements in a CSV File vulnerability in multiple products Symfony/Serializer handles serializing and deserializing data structures for Symfony, a PHP framework for web and console applications and a set of reusable PHP components. | 6.5 |
2021-05-13 | CVE-2021-21424 | Information Exposure vulnerability in multiple products Symfony is a PHP framework for web and console applications and a set of reusable PHP components. | 5.3 |
2020-09-02 | CVE-2020-15094 | Improper Cross-boundary Removal of Sensitive Data vulnerability in multiple products In Symfony before versions 4.4.13 and 5.1.5, the CachingHttpClient class from the HttpClient Symfony component relies on the HttpCache class to handle requests. | 8.8 |
2020-03-30 | CVE-2020-5275 | Incorrect Authorization vulnerability in Sensiolabs Symfony In symfony/security-http before versions 4.4.7 and 5.0.7, when a `Firewall` checks access control rule, it iterate overs each rule's attributes and stops as soon as the accessDecisionManager decides to grant access on the attribute, preventing the check of next attributes that should have been take into account in an unanimous strategy. | 8.1 |
2020-03-30 | CVE-2020-5274 | Information Exposure Through an Error Message vulnerability in Sensiolabs Symfony In Symfony before versions 5.0.5 and 4.4.5, some properties of the Exception were not properly escaped when the `ErrorHandler` rendered it stacktrace. | 5.5 |
2020-03-30 | CVE-2020-5255 | Improper Input Validation vulnerability in Sensiolabs Symfony In Symfony before versions 4.4.7 and 5.0.7, when a `Response` does not contain a `Content-Type` header, affected versions of Symfony can fallback to the format defined in the `Accept` header of the request, leading to a possible mismatch between the response's content and `Content-Type` header. | 4.3 |