Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges
Several security issues were fixed in Symfony.
Software Description:
- symfony: set of reusable components and framework for web projects
Details:
Soner Sayakci discovered that Symfony incorrectly handled cookie storage in
the web cache. An attacker could possibly use this issue to obtain
sensitive information and access unauthorized resources. (CVE-2022-24894)
Marco Squarcina discovered that Symfony incorrectly handled the storage of
user session information. An attacker could possibly use this issue to
perform a cross-site request forgery (CSRF) attack. (CVE-2022-24895)
Pierre Rudloff discovered that Symfony incorrectly checked HTML input. An
attacker could possibly use this issue to perform cross site scripting.
(CVE-2023-46734)
Vladimir Dusheyko discovered that Symfony incorrectly sanitized special
input with a PHP directive in URL query strings. An attacker could possibly
use this issue to expose sensitive information or cause a denial of
service. ...
The problem can be corrected by updating your system to the following package versions: Ubuntu 24.04 LTS php-symfony 6.4.5+dfsg-3ubuntu3+esm1 Available with Ubuntu Pro Ubuntu 22.04 LTS php-symfony 5.4.4+dfsg-1ubuntu8+esm1 Available with Ubuntu Pro Ubuntu 20.04 LTS php-symfony 4.3.8+dfsg-1ubuntu1+esm2 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes.
https://ubuntu.com/security/notices/USN-7272-1
CVE-2022-24894, CVE-2022-24895, CVE-2023-46734, CVE-2024-50340,
CVE-2024-50341, CVE-2024-50342, CVE-2024-50343, CVE-2024-50345,
CVE-2024-51996
Get the latest Linux and open source security news straight to your inbox.