nelmio/security-bundle is vulnerable to Open Redirect
31
Low Risk
Affected versions of this package are vulnerable to an open redirect due to inconsistencies in how Symfony's Request class parses URIs with special characters compared to browsers. This discrepancy allows an attacker to bypass validation and redirect users to unintended domains. The vulnerability is addressed in this patch by fixing ExternalRedirectListener to properly handle malformed URLs.
You are affected if you are using a version that falls within the vulnerable range.
nelmio/security-bundle is vulnerable to Open Redirect in versions 1.0.0 - 3.4.2.
Upgrade the nelmio/security-bundle library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant