-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2021-121edb82dd 2021-05-28 01:10:41.955482 --------------------------------------------------------------------------------
Name : php-symfony4 Product : Fedora 33 Version : 4.4.24 Release : 1.fc33 URL : https://symfony.com Summary : Symfony PHP framework (version 4) Description : Symfony PHP framework (version 4).
NOTE: Does not require PHPUnit bridge.
-------------------------------------------------------------------------------- Update Information:
**Version 4.4.24** (2021-05-19) * security **CVE-2021-21424** [Security\Core] Fix user enumeration via response body on invalid credentials (chalasr) * bug #41230 [FrameworkBundle][Validator] Fix deprecations from Doctrine Annotations+Cache (derrabus) * bug #41240 Fixed deprecation warnings about passing null as parameter (derrabus) * bug #41241 [Finder] Fix gitignore regex build with "**" (mvorisek) * bug #41224 [HttpClient] fix adding query string to relative URLs with scoped clients (nicolas-grekas) * bug #41233 [DependencyInjection][ProxyManagerBridge] Don't call class_exists() on null (derrabus) * bug #41210 [Console] Fix Windows code page support (orkan) ---- **Version 4.4.23** (2021-05-12) * security **CVE-2021-21424** [Security][Guard] Prevent user enumeration (chalasr) * bug #41176 [DependencyInjection] fix dumping service-closure-arguments (nicolas-grekas) * bug #41168 WDT: Only load "Sfjs" if it is not present already (weaverryan) * bug #41147 [Inflector][String] wrong plural form of words ending by "pectus" (makraz) * bug #41160 [HttpClient] Don't prepare the request in ScopingHttpClient (nicolas-grekas) * bug #40763 Fix/Rewrite .gitignore regex builder (mvorisek) * bug #40917 [Config][DependencyInjection] Uniformize trailing slash handling (dunglas) * bug #40699 [PropertyInfo] Make ReflectionExtractor correctly extract nullability (shiftby) * bug #40874 [PropertyInfo] fix attribute namespace with recursive traits (soullivaneuh) * bug #41099 [Cache] Check if phpredis version is compatible with stream parameter (nicolassing) * bug #41072 [VarExporter] Add support of PHP enumerations (alexandre-daubois) * bug #41105 [Inflector][String] Fixed singularize `edges`
`edge` (ruudk) * bug #41075 [ErrorHandler] Skip "same vendor" ``@method``
deprecations for `Symfony*` classes unless symfony/symfony is being tested (nicolas-grekas) -------------------------------------------------------------------------------- ChangeLog:
* Wed May 19 2021 Remi Collet remi@remirepo.net - 4.4.24-1 - update to 4.4.24 * Mon May 17 2021 Remi Collet remi@remirepo.net - 4.4.23-1 - update to 4.4.23 -------------------------------------------------------------------------------- References:
[ 1 ] Bug #1960631 - CVE-2021-21424 php-symfony: user enumeration in authentication mechanisms [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1960631 --------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-121edb82dd' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys --------------------------------------------------------------------------------
package-announce@lists.fedoraproject.org