When an application uses an HTTP basic or digest authentication, Symfony does not parse the Authorization header properly, which could be exploited in some server setups (no exploits have been demonstrated though.)
This Cyber News was published on www.tenable.com. Publication date: Thu, 30 May 2024 13:11:02 +0000