CVE-2023-46734 Information

Description

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Starting in versions 2.0.0 5.0.0 and 6.0.0 and prior to versions 4.4.51 5.4.31 and 6.3.8 some Twig filters in CodeExtension use is_safe=html but don’t actually ensure their input is safe. As of versions 4.4.51 5.4.31 and 6.3.8 Symfony now escapes the output of the affected filters.

Reference

https://github.com/symfony/symfony/security/advisories/GHSA-q847-2q57-wmr3 https://github.com/symfony/symfony/commit/5d095d5feb1322b16450284a04d6bb48d1198f54 https://github.com/symfony/symfony/commit/9da9a145ce57e4585031ad4bee37c497353eec7c

Share on: