FrameworkUserBundle Generates Error Message Containing Sensitive Information
High severity
GitHub Reviewed
Published
Jan 3, 2023
to the GitHub Advisory Database
•
Updated Mar 1, 2024
Package
Affected versions
< 1.4.0
Patched versions
1.4.0
Description
Published by the National Vulnerability Database
Jan 3, 2023
Published to the GitHub Advisory Database
Jan 3, 2023
Reviewed
Jan 10, 2023
Last updated
Mar 1, 2024
A vulnerability was found in sumocoders FrameworkUserBundle up to 1.3.x. It has been rated as problematic. Affected by this issue is some unknown functionality of the file
Resources/views/Security/login.html.twig
. The manipulation leads to information exposure through error message. Upgrading to version 1.4.0 can address this issue. The name of the patch is abe4993390ba9bd7821ab12678270556645f94c8. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-217268.NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
References