symfony/security-http is vulnerable to Insufficient Verification of Data Authenticity
81
High Risk
OidcTokenHandler registers claim checkers but does not require aud, iss, or exp to be present. A validly signed token can omit those claims and bypass intended audience, issuer, or expiry validation. Pre-fix applications can accept tokens outside the configured OpenID Connect trust constraints. The fix marks those claims mandatory during claim checking.
You are affected if you are using a version that falls within the vulnerable range.
symfony/security-http is vulnerable to Insufficient Verification of Data Authenticity in versions 6.3.0 - 6.4.39, 7.4.0 - 7.4.11 and 8.0.0 - 8.0.11.
Upgrade the symfony/security-http and/or symfony/symfony library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant