symfony/security-http Security Advisories for v2.4.0-BETA1 (5)
- 
                        [HIGH] CVE-2018-11385: Session Fixation Issue for Guard AuthenticationPKSA-r1pj-t5t2-c1n6 CVE-2018-11385 GHSA-g4rg-rw65-8hfg Affected version: >=2.4.0,<2.7.48|>=2.5.0,<2.7.48|>=2.6.0,<2.7.48|>=2.7.0,<2.7.48|>=2.8.0,<2.8.41|>=3.0.0,<3.1.0|>=3.1.0,<3.2.0|>=3.2.0,<3.3.0|>=3.3.0,<3.3.17|>=3.4.0,<3.4.11|>=4.0.0,<4.0.11 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [HIGH] CVE-2018-11406: CSRF Token FixationPKSA-4cs6-1fmm-cwn2 CVE-2018-11406 GHSA-g4g7-q726-v5hg Affected version: >=2.4.0,<2.7.48|>=2.5.0,<2.7.48|>=2.6.0,<2.7.48|>=2.7.0,<2.7.48|>=2.8.0,<2.8.41|>=3.0.0,<3.1.0|>=3.1.0,<3.2.0|>=3.2.0,<3.3.0|>=3.3.0,<3.3.17|>=3.4.0,<3.4.11|>=4.0.0,<4.0.11 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [HIGH] CVE-2016-4423: Large username storage in sessionPKSA-7y48-mnc1-xvg1 CVE-2016-4423 GHSA-whgv-8cg3-7hcm Affected version: >=2.3.0,<2.3.41|>=2.4.0,<2.5.0|>=2.5.0,<2.6.0|>=2.6.0,<2.7.0|>=2.7.0,<2.7.13|>=2.8.0,<2.8.6|>=3.0.0,<3.0.6 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [LOW] CVE-2015-8124: Session Fixation in the "Remember Me" Login FeaturePKSA-m51r-2nhf-3g41 CVE-2015-8124 GHSA-j5jh-hpr4-h332 Affected version: >=2.4.0,<2.5.0|>=2.5.0,<2.6.0|>=2.6.0,<2.6.12|>=2.7.0,<2.7.7 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [HIGH] CVE-2015-8125: Potential Remote Timing Attack Vulnerability in Security Remember-Me ServicePKSA-5979-1yv4-cw4f CVE-2015-8125 GHSA-g97c-jfx6-xvxh Affected version: >=2.4.0,<2.5.0|>=2.5.0,<2.6.0|>=2.6.0,<2.6.12|>=2.7.0,<2.7.7 Reported by: 
 GitHub, FriendsOfPHP/security-advisories