Name | CVE-2023-46734 |
Description | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Starting in versions 2.0.0, 5.0.0, and 6.0.0 and prior to versions 4.4.51, 5.4.31, and 6.3.8, some Twig filters in CodeExtension use `is_safe=html` but don't actually ensure their input is safe. As of versions 4.4.51, 5.4.31, and 6.3.8, Symfony now escapes the output of the affected filters. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
References | DLA-3664-1 |
Debian Bugs | 1055774 |
The table below lists information on source packages.
Source Package | Release | Version | Status |
---|---|---|---|
symfony (PTS) | bullseye | 4.4.19+dfsg-2+deb11u6 | fixed |
bookworm | 5.4.23+dfsg-1+deb12u2 | fixed | |
trixie | 6.4.11+dfsg-1 | fixed | |
sid | 6.4.12+dfsg-1 | fixed |
The information below is based on the following data on fixed versions.
Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
---|---|---|---|---|---|---|
symfony | source | buster | 3.4.22+dfsg-2+deb10u3 | DLA-3664-1 | ||
symfony | source | bullseye | 4.4.19+dfsg-2+deb11u4 | |||
symfony | source | bookworm | 5.4.23+dfsg-1+deb12u1 | |||
symfony | source | (unstable) | 5.4.31+dfsg-1 | 1055774 |
https://github.com/symfony/symfony/security/advisories/GHSA-q847-2q57-wmr3
https://github.com/symfony/symfony/commit/9da9a145ce57e4585031ad4bee37c497353eec7c (v4.4.51, v5.4.31, v6.3.8)