symfony/password-hasher is vulnerable to Information Disclosure
20
Low Risk
Affected versions of symfony/password-hasher are vulnerable to potential information disclosure of passwords in backtraces, which may be sent to error logging and monitoring tools like Sentry.
You are affected if you use a vulnerable version of symfony/password-hasher.
symfony/password-hasher is vulnerable to Information Disclosure in versions 5.3.0 - 6.1.11 and 7.0.0 - 7.0.8.
Upgrade symfony/password-hasher to a patch version (6.2.0 or 7.1.0).
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant