Advisory Database
  • Advisories
  • Dependency Scanning
  1. composer
  2. ›
  3. friendsofsymfony/user-bundle
  4. ›
  5. GHSA-6mjq-9x4w-m3w9

GHSA-6mjq-9x4w-m3w9: FOSUserBundle Session Hijacking Vulnerability

May 15, 2024

Versions of FOSUserBundle from 1.2.x to 1.2.4 have been found to contain a security vulnerability related to session hijacking. This issue has been addressed in version 1.2.4, and users are strongly advised to upgrade to the latest version to prevent potential session-related security risks.

References

  • github.com/FriendsOfPHP/security-advisories/blob/master/friendsofsymfony/user-bundle/2012-07-10-2.yaml
  • github.com/FriendsOfSymfony/FOSUserBundle
  • github.com/FriendsOfSymfony/FOSUserBundle/blob/master/Changelog.md
  • github.com/FriendsOfSymfony/FOSUserBundle/commit/8e412a70cafd924ad04c7325dae423048861b955
  • github.com/advisories/GHSA-6mjq-9x4w-m3w9

Code Behaviors & Features

Detect and mitigate GHSA-6mjq-9x4w-m3w9 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 1.2.0 before 1.2.4

Fixed versions

  • 1.2.4

Solution

Upgrade to version 1.2.4 or above.

Source file

packagist/friendsofsymfony/user-bundle/GHSA-6mjq-9x4w-m3w9.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 14 May 2025 12:15:08 +0000.