{"id":"GHSA-6mjq-9x4w-m3w9","summary":"FOSUserBundle Session Hijacking Vulnerability","details":"Versions of FOSUserBundle from 1.2.x to 1.2.4 have been found to contain a security vulnerability related to session hijacking. This issue has been addressed in version 1.2.4, and users are strongly advised to upgrade to the latest version to prevent potential session-related security risks.","modified":"2024-11-29T05:40:46.397504Z","published":"2024-05-15T21:42:56Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2024-05-15T21:42:56Z","nvd_published_at":null,"cwe_ids":[]},"references":[{"type":"WEB","url":"https://github.com/FriendsOfSymfony/FOSUserBundle/commit/8e412a70cafd924ad04c7325dae423048861b955"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/friendsofsymfony/user-bundle/2012-07-10-2.yaml"},{"type":"PACKAGE","url":"https://github.com/FriendsOfSymfony/FOSUserBundle"},{"type":"WEB","url":"https://github.com/FriendsOfSymfony/FOSUserBundle/blob/master/Changelog.md"}],"affected":[{"package":{"name":"friendsofsymfony/user-bundle","ecosystem":"Packagist","purl":"pkg:composer/friendsofsymfony/user-bundle"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.2.0"},{"fixed":"1.2.4"}]}],"versions":["1.2.0","v1.2.1","v1.2.2","v1.2.3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/05/GHSA-6mjq-9x4w-m3w9/GHSA-6mjq-9x4w-m3w9.json"}}],"schema_version":"1.9.0"}