symfony/security Security Advisories for v2.3.4 (7)
-
[HIGH] CVE-2018-11406: CSRF Token Fixation
PKSA-3grm-n326-q5z3 CVE-2018-11406 GHSA-g4g7-q726-v5hg
Affected version: >=2.0.0,<2.1.0|>=2.1.0,<2.2.0|>=2.2.0,<2.3.0|>=2.3.0,<2.4.0|>=2.4.0,<2.5.0|>=2.5.0,<2.6.0|>=2.6.0,<2.7.0|>=2.7.0,<2.7.48|>=2.8.0,<2.8.41|>=3.0.0,<3.1.0|>=3.1.0,<3.2.0|>=3.2.0,<3.3.0|>=3.3.0,<3.3.17|>=3.4.0,<3.4.11|>=4.0.0,<4.0.11
Reported by:
GitHub, FriendsOfPHP/security-advisories -
[HIGH] CVE-2018-11385: Session Fixation Issue for Guard Authentication
PKSA-zk3t-cmdy-sy2k CVE-2018-11385 GHSA-g4rg-rw65-8hfg
Affected version: >=2.0.0,<2.1.0|>=2.1.0,<2.2.0|>=2.2.0,<2.3.0|>=2.3.0,<2.4.0|>=2.4.0,<2.5.0|>=2.5.0,<2.6.0|>=2.6.0,<2.7.0|>=2.7.0,<2.7.48|>=2.8.0,<2.8.41|>=3.0.0,<3.1.0|>=3.1.0,<3.2.0|>=3.2.0,<3.3.0|>=3.3.0,<3.3.17|>=3.4.0,<3.4.11|>=4.0.0,<4.0.11
Reported by:
GitHub, FriendsOfPHP/security-advisories -
[HIGH] CVE-2016-4423: Large username storage in session
PKSA-9t3p-7s5c-ydgx CVE-2016-4423 GHSA-whgv-8cg3-7hcm
Affected version: >=2.3.0,<2.3.41|>=2.4.0,<2.5.0|>=2.5.0,<2.6.0|>=2.6.0,<2.7.0|>=2.7.0,<2.7.13|>=2.8.0,<2.8.6|>=3.0.0,<3.0.6
Reported by:
GitHub, FriendsOfPHP/security-advisories -
[HIGH] CVE-2016-1902: SecureRandom's fallback not secure when OpenSSL fails
PKSA-c8q4-qf8b-nmtq CVE-2016-1902 GHSA-jjx5-fq5g-8xpc
Affected version: >=2.3.0,<2.3.37|>=2.4.0,<2.5.0|>=2.5.0,<2.6.0|>=2.6.0,<2.6.13|>=2.7.0,<2.7.9
Reported by:
GitHub, FriendsOfPHP/security-advisories -
[HIGH] CVE-2015-8125: Potential Remote Timing Attack Vulnerability in Security Remember-Me Service
PKSA-krbp-gnkk-54bj CVE-2015-8125 GHSA-g97c-jfx6-xvxh
Affected version: >=2.3.0,<2.3.35|>=2.4.0,<2.5.0|>=2.5.0,<2.6.0|>=2.6.0,<2.6.12|>=2.7.0,<2.7.7
Reported by:
GitHub, FriendsOfPHP/security-advisories -
[LOW] CVE-2015-8124: Session Fixation in the "Remember Me" Login Feature
PKSA-3bc7-m4n7-t49v CVE-2015-8124 GHSA-j5jh-hpr4-h332
Affected version: >=2.3.0,<2.3.35|>=2.4.0,<2.5.0|>=2.5.0,<2.6.0|>=2.6.0,<2.6.12|>=2.7.0,<2.7.7
Reported by:
GitHub, FriendsOfPHP/security-advisories -
[MEDIUM] Possible DOS attack with long user-submitted passwords
PKSA-9qgs-5jdb-1mfq CVE-2013-5958 GHSA-cr49-fx2v-9p57
Affected version: >=2.0.0,<2.0.25|>=2.1.0,<2.1.13|>=2.2.0,<2.2.9|>=2.3.0,<2.3.6
Reported by:
GitHub, FriendsOfPHP/security-advisories