Kategorie: Symfony
Twig CVE-2024-51755: Unguarded calls to __isset() and to array-accesses in a sandbox
Affected versions Twig versions <3.11.2; >=3.12,<3.14.1 are affected by this security issue. The issue has been fixed in…
Twig CVE-2024-51754: Unguarded calls to __toString() in a sandbox when an object is in an array or an argument list
Affected versions Twig versions <3.11.2; >=3.12,<3.14.1 are affected by this security issue. The issue has been fixed in…
Symfony 7.2.0-BETA2 released
Symfony 7.2.0-BETA2 has just been released. Here is the list of the most important changes since 7.2.0-BETA1: bug…
Symfony 7.1.7 released
Symfony 7.1.7 has just been released. Here is the list of the most important changes since 7.1.6: bug…
Symfony 6.4.14 released
Symfony 6.4.14 has just been released. Here is the list of the most important changes since 6.4.13: bug…
CVE-2024-50340: Ability to change environment from query
Affected versions Symfony versions <5.4.46; >=6, <6.4.14; >=7, <7.1.7 of the Symfony Runtime component are affected by this…
CVE-2024-50342: Internal address and port enumeration allowed by NoPrivateNetworkHttpClient
Affected versions Symfony versions <5.4.46; >=6, <6.4.14; >=7, <7.1.7 of the Symfony HttpClient component are affected by this…
CVE-2024-50341: Security::login does not take into account custom user_checker
Affected versions Symfony versions >=6.2, <6.4.10; >=7.0, <7.0.10; >=7.1, <7.1.3 of the Symfony SecurityBundle component are affected by…
Symfony 5.4.46 released
Symfony 5.4.46 has just been released. Here is the list of the most important changes since 5.4.45: bug…
CVE-2024-50343: Incorrect response from Validator when input ends with `n`
Affected versions Symfony versions <5.4.43; >=6, <6.4.11; >=7, <7.1.4 of the Symfony Validator component are affected by this…