Skip to content

Security issues on 2.6.1 stable tag #814

Open
@maks-rafalko

Description

@maks-rafalko

Hi,

git branch
* (HEAD detached at 2.6.1)
app/console security:check

Symfony Security Check Report
=============================

 // Checked file: composer.lock


 [ERROR] 2 packages have known vulnerabilities.


zendframework/zend-crypt (2.4.0)
--------------------------------

 * CVE-2015-7503: Potential Information Disclosure in Zend\Crypt\PublicKey\Rsa\PublicKey
   http://framework.zend.com/security/advisory/ZF2015-10

zendframework/zend-mail (2.4.0)
-------------------------------

 * CVE-2015-3154: Potential CRLF injection attacks in mail and HTTP headers
   http://framework.zend.com/security/advisory/ZF2015-04
 * (no CVE ID): Potential remote code execution in zend-mail via Sendmail adapter
   https://framework.zend.com/security/advisory/ZF2016-04

 ! [NOTE] This checker can only detect vulnerabilities that are referenced in the SensioLabs security advisories
 !        database. Execute this command regularly to check the newly discovered vulnerabilities.

Please fix it ASAP.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions