VDB
Sign up
HIGH

GHSA-6mjq-9x4w-m3w9

FOSUserBundle Session Hijacking Vulnerability

Quick fix

GHSA-6mjq-9x4w-m3w9 — friendsofsymfony/user-bundle: upgrade to the fixed version with the command below.

composer require friendsofsymfony/user-bundle:^1.2.4

Details

Versions of FOSUserBundle from 1.2.x to 1.2.4 have been found to contain a security vulnerability related to session hijacking. This issue has been addressed in version 1.2.4, and users are strongly advised to upgrade to the latest version to prevent potential session-related security risks.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/friendsofsymfony/user-bundle
Introduced in: 1.2.0Fixed in: 1.2.4
Fixcomposer require friendsofsymfony/user-bundle:^1.2.4

References