Skip to content

Conversation

@darkpills
Copy link
Contributor

Adding another Symfony RCE gadget chain (CVE-2024-28861). This one is more powerful, since it covers all versions from 1.1 to 1.5, with no breaking changes.
A release of Symfony 1.5 has been done today (1.5.19) with the fix.

Also added the CVE number for the previous Symfony/RCE/12 chain in the information.

@cfreal cfreal merged commit 245ce48 into ambionics:master Mar 26, 2024
@cfreal
Copy link
Contributor

cfreal commented Mar 26, 2024

Hello darkpills,

Thanks!

Charles

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants