Name | CVE-2023-46734 |
Description | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Starting in versions 2.0.0, 5.0.0, and 6.0.0 and prior to versions 4.4.51, 5.4.31, and 6.3.8, some Twig filters in CodeExtension use `is_safe=html` but don't actually ensure their input is safe. As of versions 4.4.51, 5.4.31, and 6.3.8, Symfony now escapes the output of the affected filters. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
References | DLA-3664-1, ELA-1009-1 |
Debian Bugs | 1055774 |
The table below lists information on source packages.
Source Package | Release | Version | Status |
---|---|---|---|
symfony (PTS) | jessie, jessie (lts) | 2.3.21+dfsg-4+deb8u6 | vulnerable |
stretch (security) | 2.8.7+dfsg-1.3+deb9u3 | vulnerable | |
stretch (lts), stretch | 2.8.7+dfsg-1.3+deb9u5 | fixed | |
buster (security), buster, buster (lts) | 3.4.22+dfsg-2+deb10u3 | fixed | |
bullseye | 4.4.19+dfsg-2+deb11u6 | fixed | |
bookworm | 5.4.23+dfsg-1+deb12u2 | fixed | |
bookworm (security) | 5.4.23+dfsg-1+deb12u4 | fixed | |
sid, trixie | 6.4.16+dfsg-1 | fixed |
The information below is based on the following data on fixed versions.
Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
---|---|---|---|---|---|---|
symfony | source | stretch | 2.8.7+dfsg-1.3+deb9u5 | ELA-1009-1 | ||
symfony | source | buster | 3.4.22+dfsg-2+deb10u3 | DLA-3664-1 | ||
symfony | source | bullseye | 4.4.19+dfsg-2+deb11u4 | |||
symfony | source | bookworm | 5.4.23+dfsg-1+deb12u1 | |||
symfony | source | (unstable) | 5.4.31+dfsg-1 | 1055774 |
https://github.com/symfony/symfony/security/advisories/GHSA-q847-2q57-wmr3
https://github.com/symfony/symfony/commit/9da9a145ce57e4585031ad4bee37c497353eec7c (v4.4.51, v5.4.31, v6.3.8)