symfony/security Security Advisories for v4.2.6 (2)
- 
                        [MEDIUM] CVE-2021-21424: Prevent user enumeration via response content in authentication mechanismsPKSA-8ws6-qn2n-55bs CVE-2021-21424 GHSA-5pv8-ppvj-4h68 Affected version: >=2.8.0,<3.0.0|>=3.0.0,<3.1.0|>=3.1.0,<3.2.0|>=3.2.0,<3.3.0|>=3.3.0,<3.4.0|>=3.4.0,<3.4.49|>=4.0.0,<4.1.0|>=4.1.0,<4.2.0|>=4.2.0,<4.3.0|>=4.3.0,<4.4.0|>=4.4.0,<4.4.24 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [HIGH] CVE-2019-10911: Add a separator in the remember me cookie hashPKSA-cf8d-qjyv-5mqt CVE-2019-10911 GHSA-cchx-mfrc-fwqr Affected version: >=2.7.0,<2.7.51|>=2.8.0,<2.8.50|>=3.0.0,<3.1.0|>=3.1.0,<3.2.0|>=3.2.0,<3.3.0|>=3.3.0,<3.4.0|>=3.4.0,<3.4.26|>=4.0.0,<4.1.0|>=4.1.0,<4.1.12|>=4.2.0,<4.2.7 Reported by: 
 GitHub, FriendsOfPHP/security-advisories