Skip to content

Conversation

@renovate
Copy link
Contributor

@renovate renovate bot commented Nov 6, 2024

This PR contains the following updates:

Package Change Age Confidence
symfony/security-bundle (source) 7.1.2 -> 7.1.3 age confidence

GitHub Vulnerability Alerts

CVE-2024-50341

Description

The custom user_checker defined on a firewall is not called when Login Programmaticaly with the Security::login method, leading to unwanted login.

Resolution

The Security::login method now ensure to call the configured user_checker.

The patch for this issue is available here for branch 6.4.

Credits

We would like to thank Oleg Andreyev, Antoine MAKDESSI for reporting the issue and Christian Flothmann for providing the fix.


Release Notes

symfony/security-bundle (symfony/security-bundle)

v7.1.3

Compare Source

Changelog (symfony/security-bundle@v7.1.2...v7.1.3)


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@pr-reviewbot
Copy link

pr-reviewbot bot commented Nov 6, 2024

👋 Hi there!

Thanks for opening a new PR. Please, consider following this guide to make your PR easier to review.

Also, check this new feature to use markdown helpers in your PR.

@renovate renovate bot force-pushed the renovate/packagist-symfony-security-bundle-vulnerability branch from 5431965 to 1ee32d0 Compare November 18, 2024 19:46
@renovate renovate bot force-pushed the renovate/packagist-symfony-security-bundle-vulnerability branch from 1ee32d0 to 787b688 Compare August 10, 2025 15:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant