Skip to content

Conversation

@fabpot
Copy link
Member

@fabpot fabpot commented Jul 17, 2017

No description provided.

This section indexes security vulnerabilities that were fixed in Symfony
releases, starting from Symfony 1.0.0:

* Jul 17, 2017, `CVE-2017-11365: Empty passwords validation issue <http://symfony.com/blog/cve-2017-11365-empty-passwords-validation-issue>`_ (2.7.30, 2.7.31, 2.8.23, 2.8.24, 3.2.10, 3.2.11, 3.3.3, and 3.3.4)
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We should use HTTPS for the link.

Copy link
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Good catch, fixed

@xabbuh
Copy link
Member

xabbuh commented Jul 18, 2017

Thank you @fabpot.

@xabbuh xabbuh merged commit 3556e82 into symfony:2.7 Jul 18, 2017
xabbuh added a commit that referenced this pull request Jul 18, 2017
This PR was merged into the 2.7 branch. Discussion ---------- Add CVE 2017-11365 Commits ------- 3556e82 added CVE 2017-11365
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

3 participants