CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
AI Score
Confidence
High
EPSS
Percentile
17.0%
Symfony versions >=6.3.0, <6.3.8 of the Symfony Webhook component are affected by this security issue.
The issue has been fixed in Symfony 6.3.8.
The error message in WebhookController
returns unescaped user-submitted input.
WebhookController now doesn’t return any user-submitted input in its response.
The patch for this issue is available here for branch 6.3.
We would like to thank Maxime Aknin for reporting the issue and to Nicolas Grekas for providing the fix.
Log in to add a reaction to this post
add a reaction ❤️ 👍 🚀
Published in #Security Advisories
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
AI Score
Confidence
High
EPSS
Percentile
17.0%