symfony/security-http is vulnerable to Authentication Bypass by Spoofing
81
High Risk
Cas2Handler builds its CAS service URL from the incoming request host. Without trusted host configuration, the host can be attacker controlled and can change the service value sent to CAS validation. Pre-fix applications can be exposed to cross-service ticket replay when another service shares the same CAS server. The fix requires an explicit service URL instead of deriving it from the request host.
You are affected if you are using a version that falls within the vulnerable range.
symfony/security-http is vulnerable to Authentication Bypass by Spoofing in versions 7.1.0 - 7.4.11 and 8.0.0 - 8.0.11.
Upgrade the symfony/security-http and/or symfony/symfony library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant