CVE-2023-41336: symfony/ux-autocomplete Prevent injection of invalid entity ids for "autocomplete" fields

Affected Versions Versions < 2.11.1 are of the symfony/ux-autocomplete package are affected by this security issue. Description Under certain circumstances, an attacker could successfully submit an entity id for an EntityType that is not part of the… https://symfony.com/blog/cve-2023-41336-symfony-ux-autocomplete-prevent-injection-of-invalid-entity-ids-for-autocomplete-fields?utm_source=Symfony%20Blog%20Feed&utm_medium=feed

Creado 8mo | 11 sept. 2023 14:20:23


Inicia sesión para agregar comentarios

Otros mensajes en este grupo.

A Week of Symfony #907 (13-19 May 2024)

This week, the first release candidate version of Symfony 7.1 was published so you can test it in your own projects before the stable release in two weeks. Meanwhile, we continued publishing more talk

19 may. 2024 8:30:04 | Symfony
Symfony 7.1.0-RC1 released

Symfony 7.1.0-RC1 has just been released. Here is the list of the most important changes since 7.1.0-BETA1:

bug #54970 [DependencyInjection] Process PHP configs using the ContainerConfigurator (@
17 may. 2024 17:40:10 | Symfony
SymfonyOnline June 2024: Using Git magic for the Symfony mono-repo

SymfonyOnline June 2024 is just around the corner and will start on:

June 4-5: Workshop days. It is possible to attend 1 two-day training or 2 one-day trainings! June 6-7: Online conference

17 may. 2024 15:30:10 | Symfony
New in Symfony 7.1: Mailer and Notifier Integrations

Symfony provides many ready-to-use integrations with third-party services to send emails and notifications (via SMS, chat messages, or push notifications). From Google, Microsoft, and Amazon to smalle

17 may. 2024 8:40:03 | Symfony
SymfonyOnline June 2024: Front-end application development, Symfony-style(s)

SymfonyOnline June 2024 is just around the corner and will start on:

June 4-5: Workshop days. It is possible to attend 1 two-day training or 2 one-day trainings! June 6-7: Online conference

16 may. 2024 14:20:27 | Symfony
New in Symfony 7.1: Constraint Improvements

The Validator component was one of the most active components during the Symfony 7.1 development cycle. In addition to the new MacAddress and Charset constraints and the improved UniqueEntity constrai

16 may. 2024 7:30:17 | Symfony
SymfonyOnline June 2024: Announcement of workshops topics!

SymfonyOnline June 2024 is just around the corner and will start on:

June 4 & 5th: Workshop days to learn and practice in a friendly atmosphere and small groups June 6 & 7th: Online

15 may. 2024 15:20:02 | Symfony