{"id":"GHSA-6mjq-9x4w-m3w9","aliases":[],"url":"https://o3.security/vulnerability/GHSA-6mjq-9x4w-m3w9","summary":"FOSUserBundle Session Hijacking Vulnerability","details":"Versions of FOSUserBundle from 1.2.x to 1.2.4 have been found to contain a security vulnerability related to session hijacking. This issue has been addressed in version 1.2.4, and users are strongly advised to upgrade to the latest version to prevent potential session-related security risks.","published":"2024-05-15T21:42:56Z","modified":"2024-11-29T05:40:46.397504Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"friendsofsymfony/user-bundle","fixedVersion":"1.2.4"}],"fix":{"url":"https://github.com/FriendsOfSymfony/FOSUserBundle/commit/8e412a70cafd924ad04c7325dae423048861b955","label":"FriendsOfSymfony/FOSUserBundle@8e412a7"},"references":[{"type":"WEB","url":"https://github.com/FriendsOfSymfony/FOSUserBundle/commit/8e412a70cafd924ad04c7325dae423048861b955"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/friendsofsymfony/user-bundle/2012-07-10-2.yaml"},{"type":"PACKAGE","url":"https://github.com/FriendsOfSymfony/FOSUserBundle"},{"type":"WEB","url":"https://github.com/FriendsOfSymfony/FOSUserBundle/blob/master/Changelog.md"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-11-29T05:40:46.397504Z"}}