VDB
Sign up
MEDIUM6.5

GHSA-4cpv-669c-r79x

Prevent injection of invalid entity ids for "autocomplete" fields

Quick fix

GHSA-4cpv-669c-r79x — symfony/ux-autocomplete: upgrade to the fixed version with the command below.

composer require symfony/ux-autocomplete:^2.11.2

Details

### Impact Under certain circumstances, an attacker could successfully submit an entity id for an `EntityType` that is *not* part of the valid choices.

Affected applications are any that use:

* A custom `query_builder` option to limit the valid results; AND * An `EntityType` with `'autocomplete' => true` or a custom [AsEntityAutocompleteField](https://symfony.com/bundles/ux-autocomplete/current/index.html#usage-in-a-form-with-ajax).

Under this circumstance, if an id is submitted, it is accepted even if the matching record would not be returned by the custom query built with `query_builder`.

### Patches

The problem has been fixed in `symfony/ux-autocomplete` version 2.11.2.

### Workarounds Upgrade to version 2.11.2 or greater of `symfony/ux-autocomplete` or perform extra validation after submit to verify the selected option is valid.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/symfony/ux-autocomplete
Introduced in: 0Fixed in: 2.11.2
Fixcomposer require symfony/ux-autocomplete:^2.11.2

References