diff --git a/advisories/github-reviewed/2022/05/GHSA-92x6-h2gr-8gxq/GHSA-92x6-h2gr-8gxq.json b/advisories/github-reviewed/2022/05/GHSA-92x6-h2gr-8gxq/GHSA-92x6-h2gr-8gxq.json index 2b0972df261..9a0bbc35f7b 100644 --- a/advisories/github-reviewed/2022/05/GHSA-92x6-h2gr-8gxq/GHSA-92x6-h2gr-8gxq.json +++ b/advisories/github-reviewed/2022/05/GHSA-92x6-h2gr-8gxq/GHSA-92x6-h2gr-8gxq.json @@ -15,6 +15,158 @@ } ], "affected": [ + { + "package": { + "ecosystem": "Packagist", + "name": "symfony/security-csrf" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "2.7.0" + }, + { + "fixed": "2.7.38" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "symfony/security-csrf" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "2.8.0" + }, + { + "fixed": "2.8.31" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "symfony/security-csrf" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "3.0.0" + }, + { + "fixed": "3.2.14" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "symfony/security-csrf" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "3.3.0" + }, + { + "fixed": "3.3.13" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "symfony/security" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "2.7.0" + }, + { + "fixed": "2.7.38" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "symfony/security" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "2.8.0" + }, + { + "fixed": "2.8.31" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "symfony/security" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "3.0.0" + }, + { + "fixed": "3.2.14" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "symfony/security" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "3.3.0" + }, + { + "fixed": "3.3.13" + } + ] + } + ] + }, { "package": { "ecosystem": "Packagist", @@ -32,10 +184,7 @@ } ] } - ], - "database_specific": { - "last_known_affected_version_range": "<= 2.7.37" - } + ] }, { "package": { @@ -54,10 +203,7 @@ } ] } - ], - "database_specific": { - "last_known_affected_version_range": "<= 2.8.30" - } + ] }, { "package": { @@ -69,17 +215,14 @@ "type": "ECOSYSTEM", "events": [ { - "introduced": "3.2.0" + "introduced": "3.0.0" }, { "fixed": "3.2.14" } ] } - ], - "database_specific": { - "last_known_affected_version_range": "<= 3.2.13" - } + ] }, { "package": { @@ -98,10 +241,7 @@ } ] } - ], - "database_specific": { - "last_known_affected_version_range": "<= 3.3.12" - } + ] } ], "references": [ @@ -117,6 +257,18 @@ "type": "WEB", "url": "https://github.com/symfony/symfony/commit/b4dbdd7cd8732483d585eacff3428c16b07ad15e" }, + { + "type": "WEB", + "url": "https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/security-csrf/CVE-2017-16653.yaml" + }, + { + "type": "WEB", + "url": "https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/security/CVE-2017-16653.yaml" + }, + { + "type": "WEB", + "url": "https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/symfony/CVE-2017-16653.yaml" + }, { "type": "PACKAGE", "url": "https://github.com/symfony/symfony" @@ -125,6 +277,10 @@ "type": "WEB", "url": "https://symfony.com/blog/cve-2017-16653-csrf-protection-does-not-use-different-tokens-for-http-and-https" }, + { + "type": "WEB", + "url": "https://symfony.com/cve-2017-16653" + }, { "type": "WEB", "url": "https://www.debian.org/security/2018/dsa-4262" diff --git a/advisories/github-reviewed/2022/05/GHSA-r2rq-3h56-fqm4/GHSA-r2rq-3h56-fqm4.json b/advisories/github-reviewed/2022/05/GHSA-r2rq-3h56-fqm4/GHSA-r2rq-3h56-fqm4.json index 40c769625d4..3e1f1a92569 100644 --- a/advisories/github-reviewed/2022/05/GHSA-r2rq-3h56-fqm4/GHSA-r2rq-3h56-fqm4.json +++ b/advisories/github-reviewed/2022/05/GHSA-r2rq-3h56-fqm4/GHSA-r2rq-3h56-fqm4.json @@ -109,6 +109,101 @@ ] } ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "symfony/http-foundation" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "2.7.0" + }, + { + "fixed": "2.7.48" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "symfony/http-foundation" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "2.8.0" + }, + { + "fixed": "2.8.41" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "symfony/http-foundation" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "3.3.0" + }, + { + "fixed": "3.3.17" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "symfony/http-foundation" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "3.4.0" + }, + { + "fixed": "3.4.11" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "symfony/http-foundation" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "4.0.0" + }, + { + "fixed": "4.0.11" + } + ] + } + ] } ], "references": [ @@ -116,6 +211,14 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-11386" }, + { + "type": "WEB", + "url": "https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/http-foundation/CVE-2018-11386.yaml" + }, + { + "type": "WEB", + "url": "https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/symfony/CVE-2018-11386.yaml" + }, { "type": "PACKAGE", "url": "https://github.com/symfony/symfony" @@ -136,6 +239,10 @@ "type": "WEB", "url": "https://symfony.com/blog/cve-2018-11386-denial-of-service-when-using-pdosessionhandler" }, + { + "type": "WEB", + "url": "https://symfony.com/cve-2018-11386" + }, { "type": "WEB", "url": "https://www.debian.org/security/2018/dsa-4262"