symfony/security Security Advisories for v2.8.26 (8)
- 
                        [MEDIUM] CVE-2021-21424: Prevent user enumeration via response content in authentication mechanismsPKSA-8ws6-qn2n-55bs CVE-2021-21424 GHSA-5pv8-ppvj-4h68 Affected version: >=2.8.0,<3.0.0|>=3.0.0,<3.1.0|>=3.1.0,<3.2.0|>=3.2.0,<3.3.0|>=3.3.0,<3.4.0|>=3.4.0,<3.4.49|>=4.0.0,<4.1.0|>=4.1.0,<4.2.0|>=4.2.0,<4.3.0|>=4.3.0,<4.4.0|>=4.4.0,<4.4.24 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [HIGH] CVE-2019-10911: Add a separator in the remember me cookie hashPKSA-cf8d-qjyv-5mqt CVE-2019-10911 GHSA-cchx-mfrc-fwqr Affected version: >=2.7.0,<2.7.51|>=2.8.0,<2.8.50|>=3.0.0,<3.1.0|>=3.1.0,<3.2.0|>=3.2.0,<3.3.0|>=3.3.0,<3.4.0|>=3.4.0,<3.4.26|>=4.0.0,<4.1.0|>=4.1.0,<4.1.12|>=4.2.0,<4.2.7 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [MEDIUM] CVE-2018-19790: Open Redirect Vulnerability on loginPKSA-f5hy-hfjt-gmst CVE-2018-19790 GHSA-89r2-5g34-2g47 Affected version: >=2.7.38,<2.7.50|>=2.8.0,<2.8.49|>=3.0.0,<3.1.0|>=3.1.0,<3.2.0|>=3.2.0,<3.3.0|>=3.3.0,<3.4.0|>=3.4.0,<3.4.19|>=4.0.0,<4.0.15|>=4.1.0,<4.1.9|>=4.2.0,<4.2.1 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [CRITICAL] CVE-2018-11407: Unauthorized access on a misconfigured LDAP server when using an empty passwordPKSA-hdr7-z345-3h59 CVE-2018-11407 GHSA-35c5-28pg-2qg4 Affected version: >=2.8.0,<2.8.37|>=3.0.0,<3.1.0|>=3.1.0,<3.2.0|>=3.2.0,<3.3.0|>=3.3.0,<3.3.17|>=3.4.0,<3.4.7|>=4.0.0,<4.0.7 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [HIGH] CVE-2018-11406: CSRF Token FixationPKSA-3grm-n326-q5z3 CVE-2018-11406 GHSA-g4g7-q726-v5hg Affected version: >=2.0.0,<2.1.0|>=2.1.0,<2.2.0|>=2.2.0,<2.3.0|>=2.3.0,<2.4.0|>=2.4.0,<2.5.0|>=2.5.0,<2.6.0|>=2.6.0,<2.7.0|>=2.7.0,<2.7.48|>=2.8.0,<2.8.41|>=3.0.0,<3.1.0|>=3.1.0,<3.2.0|>=3.2.0,<3.3.0|>=3.3.0,<3.3.17|>=3.4.0,<3.4.11|>=4.0.0,<4.0.11 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [HIGH] CVE-2018-11385: Session Fixation Issue for Guard AuthenticationPKSA-zk3t-cmdy-sy2k CVE-2018-11385 GHSA-g4rg-rw65-8hfg Affected version: >=2.0.0,<2.1.0|>=2.1.0,<2.2.0|>=2.2.0,<2.3.0|>=2.3.0,<2.4.0|>=2.4.0,<2.5.0|>=2.5.0,<2.6.0|>=2.6.0,<2.7.0|>=2.7.0,<2.7.48|>=2.8.0,<2.8.41|>=3.0.0,<3.1.0|>=3.1.0,<3.2.0|>=3.2.0,<3.3.0|>=3.3.0,<3.3.17|>=3.4.0,<3.4.11|>=4.0.0,<4.0.11 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [MEDIUM] CVE-2017-16652: Open redirect vulnerability on security handlersPKSA-wnnc-tg88-zcy1 CVE-2017-16652 GHSA-r7p7-qr7p-2rrf Affected version: >=2.7.0,<2.7.38|>=2.8.0,<2.8.31|>=3.0.0,<3.1.0|>=3.1.0,<3.2.0|>=3.2.0,<3.2.14|>=3.3.0,<3.3.13 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [MEDIUM] CVE-2017-16653: CSRF protection does not use different tokens for HTTP and HTTPSPKSA-ctvc-mfjq-9myr CVE-2017-16653 GHSA-92x6-h2gr-8gxq Affected version: >=2.7.0,<2.7.38|>=2.8.0,<2.8.31|>=3.0.0,<3.1.0|>=3.1.0,<3.2.0|>=3.2.0,<3.2.14|>=3.3.0,<3.3.13 Reported by: 
 GitHub, FriendsOfPHP/security-advisories