symfony/security-guard Security Advisories for v3.2.0-RC1 (2)
-
[MEDIUM] CVE-2021-21424: Prevent user enumeration via response content in authentication mechanisms
PKSA-pwpg-w12v-cgx6 CVE-2021-21424 GHSA-5pv8-ppvj-4h68
Affected version: >=2.8.0,<3.0.0|>=3.0.0,<3.1.0|>=3.1.0,<3.2.0|>=3.2.0,<3.3.0|>=3.3.0,<3.4.0|>=3.4.0,<3.4.48|>=4.0.0,<4.1.0|>=4.1.0,<4.2.0|>=4.2.0,<4.3.0|>=4.3.0,<4.4.0|>=4.4.0,<4.4.23|>=5.0.0,<5.1.0|>=5.1.0,<5.2.0|>=5.2.0,<5.2.8
Reported by:
GitHub, FriendsOfPHP/security-advisories -
CVE-2018-11385: Session Fixation Issue for Guard Authentication
PKSA-hjzh-rs44-2jsh CVE-2018-11385
Affected version: >=2.8.0,<2.8.41|>=3.0.0,<3.1.0|>=3.1.0,<3.2.0|>=3.2.0,<3.3.0|>=3.3.0,<3.3.17|>=3.4.0,<3.4.11|>=4.0.0,<4.0.11
Reported by:
FriendsOfPHP/security-advisories