Update dependency symfony/http-foundation to v5.4.46 [SECURITY] #272
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
5.4.22->5.4.46GitHub Vulnerability Alerts
CVE-2024-50345
Description
The
Requestclass, does not parse URI with special characters the same way browsers do. As a result, an attacker can trick a validator relying on theRequestclass to redirect users to another domain.Resolution
The
Request::createmethods now assert the URI does not contain invalid characters as defined by https://url.spec.whatwg.org/The patch for this issue is available here for branch 5.4.
Credits
We would like to thank Sam Mush - IPASSLab && ZGC Lab for reporting the issue and Nicolas Grekas for providing the fix.
Release Notes
symfony/http-foundation (symfony/http-foundation)
v5.4.46Compare Source
Changelog (symfony/http-foundation@v5.4.45...v5.4.46)
v5.4.45Compare Source
Changelog (symfony/http-foundation@v5.4.44...v5.4.45)
v5.4.44Compare Source
Changelog (symfony/http-foundation@v5.4.43...v5.4.44)
X-Accel-Redirectand fail properly whenX-Accel-Mappingis missing (@nicolas-grekas)parse_url()bug (@nicolas-grekas)v5.4.42Compare Source
Changelog (symfony/http-foundation@v5.4.41...v5.4.42)
v5.4.40Compare Source
Changelog (symfony/http-foundation@v5.4.39...v5.4.40)
v5.4.39Compare Source
Changelog (symfony/http-foundation@v5.4.38...v5.4.39)
v5.4.38Compare Source
Changelog (symfony/http-foundation@v5.4.37...v5.4.38)
v5.4.35Compare Source
Changelog (symfony/http-foundation@v5.4.34...v5.4.35)
v5.4.34Compare Source
Changelog (symfony/http-foundation@v5.4.33...v5.4.34)
v5.4.32Compare Source
Changelog (symfony/http-foundation@v5.4.31...v5.4.32)
v5.4.31Compare Source
Changelog (symfony/http-foundation@v5.4.30...v5.4.31)
v5.4.30Compare Source
Changelog (symfony/http-foundation@v5.4.29...v5.4.30)
v5.4.28Compare Source
Changelog (symfony/http-foundation@v5.4.27...v5.4.28)
v5.4.26Compare Source
Changelog (symfony/http-foundation@v5.4.25...v5.4.26)
v5.4.25Compare Source
Changelog (symfony/http-foundation@v5.4.24...v5.4.25)
v5.4.24Compare Source
Changelog (symfony/http-foundation@v5.4.23...v5.4.24)
ArrayLoader(@rob006)execand replace it byshell_exec(@maxbeckers)isRetryabledecision of the retry strategy for re-delivery (@FlyingDR)v5.4.23Compare Source
Changelog (symfony/http-foundation@v5.4.22...v5.4.23)
Configuration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.