Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Starting in versions 2.0.0, 5.0.0, and 6.0.0 and prior to versions 4.4.51, 5.4.31, and 6.3.8, some Twig filters in CodeExtension use `is_safe=html` but don't actually ensure their input is safe. As of versions 4.4.51, 5.4.31, and 6.3.8, Symfony now escapes the output of the affected filters.
Advisories
Source ID Title
Debian DLA Debian DLA DLA-3664-1 symfony security update
EUVD EUVD EUVD-2023-3016 Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Starting in versions 2.0.0, 5.0.0, and 6.0.0 and prior to versions 4.4.51, 5.4.31, and 6.3.8, some Twig filters in CodeExtension use `is_safe=html` but don't actually ensure their input is safe. As of versions 4.4.51, 5.4.31, and 6.3.8, Symfony now escapes the output of the affected filters.
Github GHSA Github GHSA GHSA-q847-2q57-wmr3 Symfony potential Cross-site Scripting vulnerabilities in CodeExtension filters
Ubuntu USN Ubuntu USN USN-7272-1 Symfony vulnerabilities
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 13 Feb 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-02-13T17:14:33.867Z

Reserved: 2023-10-25T14:30:33.752Z

Link: CVE-2023-46734

cve-icon Vulnrichment

Updated: 2024-08-02T20:53:21.147Z

cve-icon NVD

Status : Modified

Published: 2023-11-10T18:15:09.360

Modified: 2024-11-21T08:29:11.347

Link: CVE-2023-46734

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.