Reflected cross-site scripting (XSS) In symfony/serializer
Description
Symfony potential Cross-site Scripting vulnerabilities in CodeExtension filters
Description
Some Twig filters in CodeExtension use "is_safe=html" but don't actually ensure their input is safe.
Resolution
Symfony now escapes the output of the affected filters.
The patch for this issue is available here for branch 4.4.
Credits
We would like to thank Pierre Rudloff for reporting the issue and to Nicolas Grekas for providing the fix.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
packagist | 5.4.31, 6.3.8 | ||
packagist | 5.4.31, 6.3.8 | ||
packagist | 4.4.51, 5.4.31, 6.3.8 | ||
packagist | 4.4.51, 5.4.31, 6.3.8 | ||
debian 11 | 4.4.19+dfsg-2+deb11u4 | ||
debian 12 | 5.4.23+dfsg-1+deb12u1 | ||
debian 13 | 5.4.31+dfsg-1 | ||
debian 14 | 5.4.31+dfsg-1 |
Aliases
1. 2. 3. 4. 5. 6. 7. 8. 9.
References
1. 2. 3. 4. 5.