{"id":"UBUNTU-CVE-2023-46735","details":"Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Starting in version 6.0.0 and prior to version 6.3.8, the error message in `WebhookController` returns unescaped user-submitted input. As of version 6.3.8, `WebhookController` now doesn't return any user-submitted input in its response.","modified":"2026-01-31T07:53:10.579651Z","published":"2023-11-10T18:15:00Z","withdrawn":"2025-06-23T15:56:55Z","related":["CVE-2023-46735"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-46735"},{"type":"REPORT","url":"https://github.com/symfony/symfony/security/advisories/GHSA-72x2-5c85-6wmr"},{"type":"REPORT","url":"https://github.com/symfony/symfony/commit/8128c302430394f639e818a7103b3f6815d8d962"},{"type":"REPORT","url":"https://github.com/symfony/symfony/commit/8128c302430394f639e818a7103b3f6815d8d962"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2023-46735"}],"affected":[{"package":{"name":"symfony","ecosystem":"Ubuntu:Pro:16.04:LTS","purl":"pkg:deb/ubuntu/symfony@2.7.10-0ubuntu2?arch=source&distro=esm-apps/xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.7.1+dfsg-1","2.7.5+dfsg-1","2.7.9+dfsg-1","2.7.9+dfsg-1ubuntu2","2.7.10-0ubuntu2"],"ecosystem_specific":{"ubuntu_priority":"medium"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-46735.json"}},{"package":{"name":"symfony","ecosystem":"Ubuntu:Pro:18.04:LTS","purl":"pkg:deb/ubuntu/symfony@3.4.6+dfsg-1ubuntu0.1+esm2?arch=source&distro=esm-apps/bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.8.7+dfsg-1.3ubuntu1","3.4.3+dfsg-1ubuntu4","3.4.6+dfsg-1","3.4.6+dfsg-1ubuntu0.1","3.4.6+dfsg-1ubuntu0.1+esm1","3.4.6+dfsg-1ubuntu0.1+esm2"],"ecosystem_specific":{"ubuntu_priority":"medium"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-46735.json"}},{"package":{"name":"symfony","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/symfony@4.3.8+dfsg-1ubuntu1?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["4.3.4+dfsg-1ubuntu1","4.3.8+dfsg-1ubuntu1"],"ecosystem_specific":{"ubuntu_priority":"medium"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-46735.json"}},{"package":{"name":"symfony","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/symfony@5.4.4+dfsg-1ubuntu8?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["5.2.6+dfsg-1ubuntu7","5.4.4+dfsg-1ubuntu8"],"ecosystem_specific":{"ubuntu_priority":"medium"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-46735.json"}},{"package":{"name":"symfony","ecosystem":"Ubuntu:24.10","purl":"pkg:deb/ubuntu/symfony@6.4.10+dfsg-1ubuntu1?arch=source&distro=oracular"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["6.4.5+dfsg-3ubuntu3","6.4.10+dfsg-1ubuntu1"],"ecosystem_specific":{"ubuntu_priority":"medium"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-46735.json"}},{"package":{"name":"symfony","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/symfony@6.4.5+dfsg-3ubuntu3?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["5.4.23+dfsg-1ubuntu1","5.4.35+dfsg-3ubuntu1","6.4.5+dfsg-3ubuntu2","6.4.5+dfsg-3ubuntu3"],"ecosystem_specific":{"ubuntu_priority":"medium"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-46735.json"}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}