Skip to content

security release

Choose a tag to compare

@lsmith77 lsmith77 released this 17 Jul 19:57

When working with JSONP, be aware of CVE-2014-4671 (full explanation can be found here: Abusing JSONP with Rosetta Flash). You SHOULD use NelmioSecurityBundle and disable the content type sniffing for script resources.