VDB
Sign up
MEDIUM6.1

GHSA-q847-2q57-wmr3

Symfony potential Cross-site Scripting vulnerabilities in CodeExtension filters

Quick fix

GHSA-q847-2q57-wmr3 — symfony/twig-bridge: upgrade to the fixed version with the command below.

composer require symfony/twig-bridge:^4.4.51

Details

### Description

Some Twig filters in CodeExtension use "is_safe=html" but don't actually ensure their input is safe.

### Resolution

Symfony now escapes the output of the affected filters.

The patch for this issue is available [here](https://github.com/symfony/symfony/commit/9da9a145ce57e4585031ad4bee37c497353eec7c) for branch 4.4.

### Credits

We would like to thank Pierre Rudloff for reporting the issue and to Nicolas Grekas for providing the fix.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/symfony/twig-bridge
Introduced in: 2.0.0Fixed in: 4.4.51
Fixcomposer require symfony/twig-bridge:^4.4.51
Packagist/symfony/twig-bridge
Introduced in: 5.0.0Fixed in: 5.4.31
Fixcomposer require symfony/twig-bridge:^5.4.31
Packagist/symfony/twig-bridge
Introduced in: 6.0.0Fixed in: 6.3.8
Fixcomposer require symfony/twig-bridge:^6.3.8
Packagist/symfony/symfony
Introduced in: 2.0.0Fixed in: 4.4.51
Fixcomposer require symfony/symfony:^4.4.51
Packagist/symfony/symfony
Introduced in: 5.0.0Fixed in: 5.4.31
Fixcomposer require symfony/symfony:^5.4.31
Packagist/symfony/symfony
Introduced in: 6.0.0Fixed in: 6.3.8
Fixcomposer require symfony/symfony:^6.3.8

References