MEDIUM6.1
GHSA-q847-2q57-wmr3
Symfony potential Cross-site Scripting vulnerabilities in CodeExtension filters
Quick fix
GHSA-q847-2q57-wmr3 — symfony/twig-bridge: upgrade to the fixed version with the command below.
composer require symfony/twig-bridge:^4.4.51Details
### Description
Some Twig filters in CodeExtension use "is_safe=html" but don't actually ensure their input is safe.
### Resolution
Symfony now escapes the output of the affected filters.
The patch for this issue is available [here](https://github.com/symfony/symfony/commit/9da9a145ce57e4585031ad4bee37c497353eec7c) for branch 4.4.
### Credits
We would like to thank Pierre Rudloff for reporting the issue and to Nicolas Grekas for providing the fix.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/symfony/twig-bridge
Introduced in:
2.0.0Fixed in: 4.4.51Fix
composer require symfony/twig-bridge:^4.4.51Packagist/symfony/twig-bridge
Introduced in:
5.0.0Fixed in: 5.4.31Fix
composer require symfony/twig-bridge:^5.4.31Packagist/symfony/twig-bridge
Introduced in:
6.0.0Fixed in: 6.3.8Fix
composer require symfony/twig-bridge:^6.3.8Packagist/symfony/symfony
Introduced in:
2.0.0Fixed in: 4.4.51Fix
composer require symfony/symfony:^4.4.51Packagist/symfony/symfony
Introduced in:
5.0.0Fixed in: 5.4.31Fix
composer require symfony/symfony:^5.4.31Packagist/symfony/symfony
Introduced in:
6.0.0Fixed in: 6.3.8Fix
composer require symfony/symfony:^6.3.8References
- https://github.com/symfony/symfony/security/advisories/GHSA-q847-2q57-wmr3[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2023-46734[ADVISORY]
- https://github.com/symfony/symfony/commit/5d095d5feb1322b16450284a04d6bb48d1198f54[WEB]
- https://github.com/symfony/symfony/commit/9da9a145ce57e4585031ad4bee37c497353eec7c[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/symfony/CVE-2023-46734.yaml[WEB]
- https://github.com/symfony/symfony[PACKAGE]
- https://lists.debian.org/debian-lts-announce/2023/11/msg00019.html[WEB]
- https://symfony.com/cve-2023-46734[WEB]