Vulnerabilities > Sensiolabs > Symfony > High
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-02-03 | CVE-2022-24894 | Improper Authorization vulnerability in Sensiolabs Symfony Symfony is a PHP framework for web and console applications and a set of reusable PHP components. | 8.8 |
2023-02-03 | CVE-2022-24895 | Session Fixation vulnerability in Sensiolabs Symfony Symfony is a PHP framework for web and console applications and a set of reusable PHP components. | 8.8 |
2020-09-02 | CVE-2020-15094 | Improper Cross-boundary Removal of Sensitive Data vulnerability in multiple products In Symfony before versions 4.4.13 and 5.1.5, the CachingHttpClient class from the HttpClient Symfony component relies on the HttpCache class to handle requests. | 8.8 |
2020-03-30 | CVE-2020-5275 | Incorrect Authorization vulnerability in Sensiolabs Symfony In symfony/security-http before versions 4.4.7 and 5.0.7, when a `Firewall` checks access control rule, it iterate overs each rule's attributes and stops as soon as the accessDecisionManager decides to grant access on the attribute, preventing the check of next attributes that should have been take into account in an unanimous strategy. | 8.1 |
2019-11-21 | CVE-2019-18888 | Argument Injection or Modification vulnerability in multiple products An issue was discovered in Symfony 2.8.0 through 2.8.50, 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4.3.7. | 7.5 |
2019-11-21 | CVE-2019-18887 | Information Exposure Through Discrepancy vulnerability in multiple products An issue was discovered in Symfony 2.8.0 through 2.8.50, 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4.3.7. | 8.1 |
2019-11-21 | CVE-2019-11325 | Improper Encoding or Escaping of Output vulnerability in Sensiolabs Symfony An issue was discovered in Symfony before 4.2.12 and 4.3.x before 4.3.8. | 7.5 |
2019-05-23 | CVE-2017-11365 | Improper Access Control vulnerability in Sensiolabs Symfony Certain Symfony products are affected by: Incorrect Access Control. | 7.5 |
2019-05-16 | CVE-2019-10913 | Cross-site Scripting vulnerability in Sensiolabs Symfony In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, HTTP Methods provided as verbs or using the override header may be treated as trusted input, but they are not validated, possibly causing SQL injection or XSS. | 7.5 |
2019-05-16 | CVE-2019-10912 | Deserialization of Untrusted Data vulnerability in Sensiolabs Symfony In Symfony before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, it is possible to cache objects that may contain bad user input. | 7.1 |