Skip to content

Symfony Blog

All about Symfony releases, new Symfony features, and other important announcements

CVE-2019-11325 fixes an issue where some strings were not properly escaped while dumping, leading to possible remote code execution.
November 13, 2019 #Security Advisories
CVE-2019-18886 fixes an issue where one could enumerate users using the switch user functionality as different behaviour would occur when a user existed compared to when a user did not
November 13, 2019 #Security Advisories
CVE-2019-18887 fixes an issue where one could guess the signature of an URI using a remote timing attack.
November 13, 2019 #Security Advisories
November 13, 2019 #Releases
CVE-2019-18889 fixes an issue where the destructor of TagAwareAdapter execute callables stored in properties, leading to possible remote code execution when an external payload is unserialized.
November 13, 2019 #Security Advisories
November 13, 2019 #Releases
November 13, 2019 #Releases
November 13, 2019 #Releases
November 13, 2019 #Releases
November 13, 2019 #Releases