GHSA-4cpv-669c-r79x
Prevent injection of invalid entity ids for "autocomplete" fields
Quick fix
GHSA-4cpv-669c-r79x — symfony/ux-autocomplete: upgrade to the fixed version with the command below.
composer require symfony/ux-autocomplete:^2.11.2Details
### Impact Under certain circumstances, an attacker could successfully submit an entity id for an `EntityType` that is *not* part of the valid choices.
Affected applications are any that use:
* A custom `query_builder` option to limit the valid results; AND * An `EntityType` with `'autocomplete' => true` or a custom [AsEntityAutocompleteField](https://symfony.com/bundles/ux-autocomplete/current/index.html#usage-in-a-form-with-ajax).
Under this circumstance, if an id is submitted, it is accepted even if the matching record would not be returned by the custom query built with `query_builder`.
### Patches
The problem has been fixed in `symfony/ux-autocomplete` version 2.11.2.
### Workarounds Upgrade to version 2.11.2 or greater of `symfony/ux-autocomplete` or perform extra validation after submit to verify the selected option is valid.
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 2.11.2composer require symfony/ux-autocomplete:^2.11.2References
- https://github.com/symfony/ux-autocomplete/security/advisories/GHSA-4cpv-669c-r79x[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2023-41336[ADVISORY]
- https://github.com/symfony/ux-autocomplete/commit/fabcb2eee14b9e84a45b276711853a560b5d770c[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/ux-autocomplete/CVE-2023-41336.yaml[WEB]
- https://github.com/symfony/ux-autocomplete[PACKAGE]
- https://symfony.com/bundles/ux-autocomplete/current/index.html#usage-in-a-form-with-ajax[WEB]