Skip to content

Symfony Open Redirect

Moderate severity GitHub Reviewed Published May 14, 2022 to the GitHub Advisory Database • Updated Feb 7, 2024

Package

composer symfony/security-bundle (Composer)

Affected versions

>= 2.7.0, < 2.7.48
>= 2.8.0, < 2.8.41
>= 3.3.0, < 3.3.17
>= 3.4.0, < 3.4.11
>= 4.0.0, < 4.0.11

Patched versions

2.7.48
2.8.41
3.3.17
3.4.11
4.0.11
composer symfony/symfony (Composer)
>= 2.7.0, < 2.7.48
>= 2.8.0, < 2.8.41
>= 3.3.0, < 3.3.17
>= 3.4.0, < 3.4.11
>= 4.0.0, < 4.0.11
2.7.48
2.8.41
3.3.17
3.4.11
4.0.11
Published by the National Vulnerability Database Jun 13, 2018
Published to the GitHub Advisory Database May 14, 2022
Reviewed Jul 24, 2023
Last updated Feb 7, 2024

Severity

Moderate
6.1
/ 10

CVSS base metrics

Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Weaknesses

CVE ID

CVE-2018-11408

GHSA ID

GHSA-7hwc-2cq4-6x2w

Source code

Checking history
See something to contribute? Suggest improvements for this vulnerability.