CVE-2023-46735: Symfony potential Cross-site Scripting in WebhookController
(updated )
The error message in WebhookController returns unescaped user-submitted input.
References
- github.com/FriendsOfPHP/security-advisories/blob/master/symfony/symfony/CVE-2023-46735.yaml
- github.com/advisories/GHSA-72x2-5c85-6wmr
- github.com/symfony/symfony
- github.com/symfony/symfony/commit/8128c302430394f639e818a7103b3f6815d8d962
- github.com/symfony/symfony/security/advisories/GHSA-72x2-5c85-6wmr
- nvd.nist.gov/vuln/detail/CVE-2023-46735
- symfony.com/cve-2023-46735
Detect and mitigate CVE-2023-46735 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →