GHSA-rjpm-qmq7-q85w high
Symfony XXE security vulnerability
Affected range
ECOSYSTEM: introduced 2.0.0; fixed 2.0.17>=2.0.0,<2.0.17Fixed versions: 2.0.17
Maps an HTTP request to a set of configuration variables
Evidence path
RequestGuard keeps these facts separate. A KEV match refers to a CVE, while OSV supplies the package and version match.
Latest version
8.1.6
No matching published advisory returned
Known exploitation
No KEV match
Checked by exact CVE identifier
Highest advisory severity
High
4 active advisories
The registry confirms the version, then OSV checks advisories for that exact value.
Published records
Affected range
ECOSYSTEM: introduced 2.0.0; fixed 2.0.17>=2.0.0,<2.0.17Fixed versions: 2.0.17
Affected range
ECOSYSTEM: introduced 0; fixed 5.4.53ECOSYSTEM: introduced 6.0.0; fixed 6.4.41ECOSYSTEM: introduced 7.0.0; fixed 7.4.13ECOSYSTEM: introduced 8.0.0; fixed 8.0.13>=2.0.0,<3.0.0|>=3.0.0,<4.0.0|>=4.0.0,<5.0.0|>=5.0.0,<5.1.0|>=5.1.0,<5.2.0|>=5.2.0,<5.3.0|>=5.3.0,<5.4.0|>=5.4.0,<5.4.53|>=6.0.0,<6.1.0|>=6.1.0,<6.2.0|>=6.2.0,<6.3.0|>=6.3.0,<6.4.0|>=6.4.0,<6.4.41|>=7.0.0,<7.1.0|>=7.1.0,<7.2.0|>=7.2.0,<7.3.0|>=7.3.0,<7.4.0|>=7.4.0,<7.4.13|>=8.0.0,<8.0.13Fixed versions: 5.4.53, 6.4.41, 7.4.13, 8.0.13
Affected range
ECOSYSTEM: introduced 0; fixed 5.4.52ECOSYSTEM: introduced 6.0.0; fixed 6.4.40ECOSYSTEM: introduced 7.0.0; fixed 7.4.12ECOSYSTEM: introduced 8.0.0; fixed 8.0.12>=2.0.0,<3.0.0|>=3.0.0,<4.0.0|>=4.0.0,<5.0.0|>=5.0.0,<5.1.0|>=5.1.0,<5.2.0|>=5.2.0,<5.3.0|>=5.3.0,<5.4.0|>=5.4.0,<5.4.52|>=6.0.0,<6.1.0|>=6.1.0,<6.2.0|>=6.2.0,<6.3.0|>=6.3.0,<6.4.0|>=6.4.0,<6.4.40|>=7.0.0,<7.1.0|>=7.1.0,<7.2.0|>=7.2.0,<7.3.0|>=7.3.0,<7.4.0|>=7.4.0,<7.4.12|>=8.0.0,<8.0.12Fixed versions: 5.4.52, 6.4.40, 7.4.12, 8.0.12
Affected range
ECOSYSTEM: introduced 2.0.0; fixed 2.0.19>=2.0.0,<2.0.19Fixed versions: 2.0.19