← Back

CVE-2023-46734

nvd nist
Published: Nov 10, 2023Modified: Jul 29, 2026

JSON object

Loading...
6.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: NVD

Description

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Starting in versions 2.0.0, 5.0.0, and 6.0.0 and prior to versions 4.4.51, 5.4.31, and 6.3.8, some Twig filters in CodeExtension use `is_safe=html` but don't actually ensure their input is safe. As of versions 4.4.51, 5.4.31, and 6.3.8, Symfony now escapes the output of the affected filters.

Affected (7)

1 product
Debian Linux
1 product
Symfony
1 product
Twig Bridge
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 10.0
Configuration B
6 vulnerable
Vulnerable SoftwareAffected Versions
Sensiolabs
From 2.0.0 to 4.4.51
From 5.0.0 to 5.4.31
From 6.0.0 to 6.3.8
Symfony
From 2.0.0 to 4.4.51
From 5.0.0 to 5.4.31
From 6.0.0 to 6.3.8

References (8)

Timeline

No history available yet.