If you have found a security issue in Symfony, please send the details to security [at] symfony.com and don't disclose it publicly until we can provide a fix for it.

CVE-2017-16653: CSRF protection does not use different tokens for HTTP and HTTPS

CVE-2017-16653 fixes CSRF protection which did not use different tokens for HTTP and HTTPS.

CVE-2017-16652: Open redirect vulnerability on security handlers

CVE-2017-16652 fixes an open redirect vulnerability on DefaultAuthenticationSuccessHandler and DefaultAuthenticationFailureHandler

CVE-2017-16654: Intl bundle readers breaking out of paths

CVE-2017-16654 fixes the possibility for the Intl bundle reader to break out of paths.

CVE-2017-16790: Ensure that submitted data are uploaded files

CVE-2017-16790 checks that submitted data are uploaded files.

CVE-2017-11365: Empty passwords validation issue

CVE-2017-11365 fixes a regression which allows empty passwords to be always valid for any user.

CVE-2016-2403: Unauthorized access on a misconfigured Ldap server when using an empty password

CVE-2016-2403 fixes an unauthorized access on a misconfigured Ldap server when using an empty password

CVE-2016-4423: Large username storage in session

CVE-2016-4423 avoids storing large usernames in UsernamePasswordFormAuthenticationListener.

CVE-2016-1902: SecureRandom's fallback not secure when OpenSSL fails

CVE-2016-1902 fixes the SecureRandom class when OpenSSL fails.

CVE-2015-8124: Session Fixation in the "Remember Me" Login Feature

CVE-2015-8124 fixes a session fixation in the "Remember Me" login feature.

CVE-2015-8125: Potential Remote Timing Attack Vulnerability in Security Remember-Me Service

CVE-2015-8125 fixes a potential remote timing attack vulnerability in Security remember-me service.