VDB
Sign up
HIGH7.6

GHSA-g4m9-5hpf-hx72

Firewall configured with unanimous strategy was not actually unanimous in Symfony

Quick fix

GHSA-g4m9-5hpf-hx72 — symfony/security: upgrade to the fixed version with the command below.

composer require symfony/security:^4.4.7

Details

Description -----------

On Symfony before 4.4.0, when a `Firewall` checks an access control rule (using the unanimous strategy), it iterates over all rule attributes and grant access only if *all* calls to the `accessDecisionManager` decide to grant access.

As of Symfony 4.4.0, a bug was introduced that prevents the check of attributes as soon as `accessDecisionManager` decide to grant access on one attribute.

Resolution ----------

The `accessDecisionManager` is now called with all attributes at once, allowing the unanimous strategy being applied on each attribute.

The patch for this issue is available [here](https://github.com/symfony/symfony/commit/c935e4a3fba6cc2ab463a6ca382858068d63cebf) for the 4.4 branch.

Credits -------

I would like to thank Antonio J. García Lagar for reporting & Robin Chalas for fixing the issue.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/symfony/security
Introduced in: 4.4.0Fixed in: 4.4.7
Fixcomposer require symfony/security:^4.4.7
Packagist/symfony/security
Introduced in: 5.0.0Fixed in: 5.0.7
Fixcomposer require symfony/security:^5.0.7
Packagist/symfony/security-http
Introduced in: 4.4.0Fixed in: 4.4.7
Fixcomposer require symfony/security-http:^4.4.7
Packagist/symfony/security-http
Introduced in: 5.0.0Fixed in: 5.0.7
Fixcomposer require symfony/security-http:^5.0.7
Packagist/symfony/symfony
Introduced in: 4.4.0Fixed in: 4.4.7
Fixcomposer require symfony/symfony:^4.4.7
Packagist/symfony/symfony
Introduced in: 5.0.0Fixed in: 5.0.7
Fixcomposer require symfony/symfony:^5.0.7

References