Skip to content

Symfony CSRF Vulnerability

Moderate severity GitHub Reviewed Published May 13, 2022 to the GitHub Advisory Database • Updated Feb 7, 2024

Package

composer symfony/security (Composer)

Affected versions

>= 2.7.0, < 2.7.38
>= 2.8.0, < 2.8.31
>= 3.0.0, < 3.2.14
>= 3.3.0, < 3.3.13

Patched versions

2.7.38
2.8.31
3.2.14
3.3.13
composer symfony/security-csrf (Composer)
>= 2.7.0, < 2.7.38
>= 2.8.0, < 2.8.31
>= 3.0.0, < 3.2.14
>= 3.3.0, < 3.3.13
2.7.38
2.8.31
3.2.14
3.3.13
composer symfony/symfony (Composer)
>= 2.7.0, < 2.7.38
>= 2.8.0, < 2.8.31
>= 3.0.0, < 3.2.14
>= 3.3.0, < 3.3.13
2.7.38
2.8.31
3.2.14
3.3.13
Published by the National Vulnerability Database Aug 6, 2018
Published to the GitHub Advisory Database May 13, 2022
Reviewed Jul 26, 2023
Last updated Feb 7, 2024

Severity

Moderate
5.9
/ 10

CVSS base metrics

Attack vector
Network
Attack complexity
High
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Weaknesses

CVE ID

CVE-2017-16653

GHSA ID

GHSA-92x6-h2gr-8gxq

Source code

Checking history
See something to contribute? Suggest improvements for this vulnerability.