HIGH
GHSA-6mjq-9x4w-m3w9
FOSUserBundle Session Hijacking Vulnerability
Quick fix
GHSA-6mjq-9x4w-m3w9 — friendsofsymfony/user-bundle: upgrade to the fixed version with the command below.
composer require friendsofsymfony/user-bundle:^1.2.4Details
Versions of FOSUserBundle from 1.2.x to 1.2.4 have been found to contain a security vulnerability related to session hijacking. This issue has been addressed in version 1.2.4, and users are strongly advised to upgrade to the latest version to prevent potential session-related security risks.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/friendsofsymfony/user-bundle
Introduced in:
1.2.0Fixed in: 1.2.4Fix
composer require friendsofsymfony/user-bundle:^1.2.4References
- https://github.com/FriendsOfSymfony/FOSUserBundle/commit/8e412a70cafd924ad04c7325dae423048861b955[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/friendsofsymfony/user-bundle/2012-07-10-2.yaml[WEB]
- https://github.com/FriendsOfSymfony/FOSUserBundle[PACKAGE]
- https://github.com/FriendsOfSymfony/FOSUserBundle/blob/master/Changelog.md[WEB]