symfony/security-http/.../security-http vulnerabilities

Direct Vulnerabilities

Known vulnerabilities in the symfony/security-http package. This does not include vulnerabilities belonging to this package’s dependencies.

How to fix?

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

Fix for free
VulnerabilityVulnerable Version
  • H
Authentication Bypass dsfsdf

>=5.3.0, <5.4.47>=6.0.0-BETA1, <6.4.15>=7.0.0-BETA1, <7.1.8
  • M
Session Fixation dsfsdf

>=5.4.21, <5.4.31>=6.2.7, <6.3.8
  • M
Improper Authentication dsfsdf

>=5.3.0, <5.3.2
  • M
Information Exposure dsfsdf

>=2.8.0, <3.4.48>=4.0.0, <4.4.23>=5.0.0, <5.2.8
  • H
Improper Authorization dsfsdf

>=4.4.0, <4.4.7
  • M
User Enumeration dsfsdf

>=4.2.0, <4.2.12>=4.3.0, <4.3.8
  • M
Access Control Bypass dsfsdf

>=4.2.0, <4.2.7
  • M
Open Redirect dsfsdf

>=2.7.0, <2.7.50>=2.8.0, <2.8.49>=3.0.0, <3.4.20>=4.0.0, <4.0.15>=4.1.0, <4.1.9
  • H
Session Fixation dsfsdf

<2.7.48>=2.8.0, <2.8.41>=3.0.0, <3.3.17>=3.4.0, <3.4.11>=4.0.0, <4.0.11
  • H
CSRF Token Fixation dsfsdf

<2.7.48>=2.8.0, <2.8.41>=3.0.0, <3.3.17>=3.4.0, <3.4.11>=4.0.0, <4.0.11
  • M
Open Redirect dsfsdf

>=2.7.0, <2.7.38>=2.8.0, <2.8.31>=3, <3.1.0>=3.1.0, <3.2.0>=3.2.0, <3.2.14>=3.3.0, <3.3.13>=3.4-BETA0, <3.4-BETA5>=4.0-BETA0, <4.0-BETA5
  • H
Denial of Service (DoS) dsfsdf

>=2.3.0, <2.3.41>=2.6.0, <2.7.0>=2.4.0, <2.5.0>=2.7.0, <2.7.13>=2.5.0, <2.6.0>=2.8.0, <2.8.6>=3, <3.0.6
  • H
Timing Attack dsfsdf

>=2.6.0, <2.6.12>=2.4.0, <2.5.0>=2.7.0, <2.7.7>=2.5.0, <2.6.0
  • M
Session Fixation dsfsdf

>=2.6.0, <2.6.12>=2.4.0, <2.5.0>=2.7.0, <2.7.7>=2.5.0, <2.6.0