Symfony Security Component - HTTP Integration
100%
Total Score
100
100
100
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2025-10856 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. symfony/security-http is vulnerable to Authentication Bypass by Primary Weakness in versions 7.3.0 - 7.3.7 and 8.0.0 - 8.0.0. | 7.3.0 - 7.3.78.0.0 - 8.0.0 | High |
AIKIDO-2025-10057 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. symfony/security-http is vulnerable to Generation of Error Message Containing Sensitive Information in versions 2.1.0 - 6.4.17. | 2.1.0 - 6.4.17 | Low |
CVE-2024-51996 symfony/security-http is vulnerable to Improper Authentication in versions 5.3.0 - 5.4.47, 6.0.0-BETA1 - 6.4.15 and 7.0.0-BETA1 - 7.1.8. | 5.3.0 - 5.4.476.0.0-BETA1 - 6.4.157.0.0-BETA1 - 7.1.8 | High |
CVE-2023-46733 symfony/security-http is vulnerable to Session Fixation in versions 5.4.21 - 5.4.31 and 6.2.7 - 6.3.8. | 5.4.21 - 5.4.316.2.7 - 6.3.8 | Medium |
CVE-2016-4423 symfony/security-http is vulnerable to Security Vulnerability in versions 2.3.0 - 2.3.41, 2.4.0 - 2.7.13, 2.8.0 - 2.8.6 and 3.0.0 - 3.0.6. | 2.3.0 - 2.3.412.4.0 - 2.7.132.8.0 - 2.8.6 +1 more | High |
| Dependency | Last Release | Score |
|---|---|---|
symfony/http-kernel Version ^7.4|^8.0 | — | — |
symfony/security-core Version ^7.4|^8.0 | — | — |
symfony/http-foundation Version ^7.4|^8.0 | — | — |
symfony/property-access Version ^7.4|^8.0 | — | — |
symfony/polyfill-mbstring Version ^1.0 | — | — |
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant