CVE-2023-46734 Information
Nov 13, 2023
cve
Description
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Starting in versions 2.0.0 5.0.0 and 6.0.0 and prior to versions 4.4.51 5.4.31 and 6.3.8 some Twig filters in CodeExtension use is_safe=html but don’t actually ensure their input is safe. As of versions 4.4.51 5.4.31 and 6.3.8 Symfony now escapes the output of the affected filters.
Reference
https://github.com/symfony/symfony/security/advisories/GHSA-q847-2q57-wmr3 https://github.com/symfony/symfony/commit/5d095d5feb1322b16450284a04d6bb48d1198f54 https://github.com/symfony/symfony/commit/9da9a145ce57e4585031ad4bee37c497353eec7c
Share on: