Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 6.4.40, 7.4.12, and 8.0.12, the Mailjet mailer bridge and LOX24 notifier bridge webhook pars…
Medium CVSS 5.3
Summary
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 6.4.40, 7.4.12, and 8.0.12, the Mailjet mailer bridge and LOX24 notifier bridge webhook parsers received configured webhook secrets but did not verify them, allowing unauthenticated POST requests to inject forged Mailjet and LOX24 event payloads. This issue is fixed in versions 6.4.40, 7.4.12, and 8.0.12.
In-depth triage · Auto channel
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
Sources
- NVD DATABASE
Original Links
- https://github.com/symfony/symfony/commit/3e52bf5ab733ee32e35eeeeb2631d859c941838e Patch
- https://github.com/symfony/symfony/commit/4aaa45dd054f73445f1ab254968b7e60b546cc77 Patch
- https://github.com/symfony/symfony/releases/tag/v6.4.40 Release Notes
- https://github.com/symfony/symfony/releases/tag/v7.4.12 Release Notes
- https://github.com/symfony/symfony/releases/tag/v8.0.12 Release Notes
- https://github.com/symfony/symfony/security/advisories/GHSA-64hg-93w9-fc35 Patch
Timeline
- nvd_ingest NVD