QID 994889
Date Published: 2023-08-21
QID 994889: PHP (Composer) Security Update for symfony/symfony (GHSA-83c3-qx27-2rwr)
Symfony 2.0.x before 2.0.20 does not process URL encoded data consistently within the Routing and Security components, which allows remote attackers to bypass intended URI restrictions via a doubly encoded string.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-83c3-qx27-2rwr for updates and patch information.
Vendor References
- GHSA-83c3-qx27-2rwr -
github.com/advisories/GHSA-83c3-qx27-2rwr
CVEs related to QID 994889
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-83c3-qx27-2rwr | symfony/symfony |
|