Skip to content
This repository has been archived by the owner on Apr 9, 2019. It is now read-only.

[Security] Bump symfony/http-foundation from 4.0.8 to 4.2.0 #35

Conversation

dependabot-preview[bot]
Copy link

Bumps symfony/http-foundation from 4.0.8 to 4.2.0. This update includes security fixes.

Vulnerabilities fixed

Sourced from The PHP Security Advisories Database.

CVE-2018-14773: Remove support for legacy and risky HTTP headers

Affected versions: >=2.0.0, <2.1.0; >=2.1.0, <2.2.0; >=2.2.0, <2.3.0; >=2.3.0, <2.4.0; >=2.4.0, <2.5.0; >=2.5.0, <2.6.0; >=2.6.0, <2.7.0; >=2.7.0, <2.7.49; >=2.8.0, <2.8.44; >=3.0.0, <3.1.0; >=3.1.0, <3.2.0; >=3.2.0, <3.3.0; >=3.3.0, <3.3.18; >=3.4.0, <3.4.14; >=4.0.0, <4.0.14; >=4.1.0, <4.1.3

Sourced from The PHP Security Advisories Database.

CVE-2018-11386: Denial of service when using PDOSessionHandler

Affected versions: >=2.0.0, <2.7.48; >=2.1.0, <2.7.48; >=2.2.0, <2.7.48; >=2.3.0, <2.7.48; >=2.4.0, <2.7.48; >=2.5.0, <2.7.48; >=2.6.0, <2.7.48; >=2.7.0, <2.7.48; >=2.8.0, <2.8.41; >=3.0.0, <3.1.0; >=3.1.0, <3.2.0; >=3.2.0, <3.3.0; >=3.3.0, <3.3.17; >=3.4.0, <3.4.11; >=4.0.0, <4.0.11

Sourced from The PHP Security Advisories Database.

CVE-2018-11386: Denial of service when using PDOSessionHandler

Affected versions: >=2.0.0, <2.1.0; >=2.1.0, <2.2.0; >=2.2.0, <2.3.0; >=2.3.0, <2.4.0; >=2.4.0, <2.5.0; >=2.5.0, <2.6.0; >=2.6.0, <2.7.0; >=2.7.0, <2.7.48; >=2.8.0, <2.8.41; >=3.0.0, <3.1.0; >=3.1.0, <3.2.0; >=3.2.0, <3.3.0; >=3.3.0, <3.3.17; >=3.4.0, <3.4.11; >=4.0.0, <4.0.11

Changelog

Sourced from symfony/http-foundation's changelog.

4.2.0

  • the default value of the "$secure" and "$samesite" arguments of Cookie's constructor
    will respectively change from "false" to "null" and from "null" to "lax" in Symfony
    5.0, you should define their values explicitly or use "Cookie::create()" instead.
  • added matchPort() in RequestMatcher

4.1.3

  • [BC BREAK] Support for the IIS-only X_ORIGINAL_URL and X_REWRITE_URL
    HTTP headers has been dropped for security reasons.

4.1.0

  • Query string normalization uses parse_str() instead of custom parsing logic.
  • Passing the file size to the constructor of the UploadedFile class is deprecated.
  • The getClientSize() method of the UploadedFile class is deprecated. Use getSize() instead.
  • added RedisSessionHandler to use Redis as a session storage
  • The get() method of the AcceptHeader class now takes into account the
    * and */* default values (if they are present in the Accept HTTP header)
    when looking for items.
  • deprecated Request::getSession() when no session has been set. Use Request::hasSession() instead.
  • added CannotWriteFileException, ExtensionFileException, FormSizeFileException,
    IniSizeFileException, NoFileException, NoTmpDirFileException, PartialFileException to
    handle failed UploadedFile.
  • added MigratingSessionHandler for migrating between two session handlers without losing sessions
  • added HeaderUtils.

4.0.0

  • the Request::setTrustedHeaderName() and Request::getTrustedHeaderName()
    methods have been removed
  • the Request::HEADER_CLIENT_IP constant has been removed, use
    Request::HEADER_X_FORWARDED_FOR instead
  • the Request::HEADER_CLIENT_HOST constant has been removed, use
    Request::HEADER_X_FORWARDED_HOST instead
  • the Request::HEADER_CLIENT_PROTO constant has been removed, use
    Request::HEADER_X_FORWARDED_PROTO instead
  • the Request::HEADER_CLIENT_PORT constant has been removed, use
    Request::HEADER_X_FORWARDED_PORT instead
  • checking for cacheable HTTP methods using the Request::isMethodSafe()
    method (by not passing false as its argument) is not supported anymore and
    throws a \BadMethodCallException
  • the WriteCheckSessionHandler, NativeSessionHandler and NativeProxy classes have been removed
  • setting session save handlers that do not implement \SessionHandlerInterface in
    NativeSessionStorage::setSaveHandler() is not supported anymore and throws a
... (truncated)
Commits
  • 1b31f30 Merge branch '4.1'
  • 26062b9 Merge branch '3.4' into 4.1
  • ea61dd5 Merge branch '2.8' into 3.4
  • d0ab719 Doc fix: clarify isMethodCacheable() returns true only for GET & HEAD
  • fdc6033 [HttpFoundation] Fix trailing space for mime-type with parameters
  • fbf0364 [HttpFoundation] Fixed absolute Request URI with default port
  • b5f0424 Merge branch '4.1'
  • 8b315e0 Merge branch '3.4' into 4.1
  • fdf102d Merge branch '2.8' into 3.4
  • f54b7ef Bump phpunit XSD version to 5.2
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot ignore this [patch|minor|major] version will close this PR and stop Dependabot creating any more for this minor/major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
  • @dependabot use these labels will set the current labels as the default for future PRs for this repo and language
  • @dependabot use these reviewers will set the current reviewers as the default for future PRs for this repo and language
  • @dependabot use these assignees will set the current assignees as the default for future PRs for this repo and language
  • @dependabot use this milestone will set the current milestone as the default for future PRs for this repo and language
  • @dependabot badge me will comment on this PR with code to add a "Dependabot enabled" badge to your readme

Additionally, you can set the following in your Dependabot dashboard:

  • Update frequency (including time of day and day of week)
  • Automerge options (never/patch/minor, and dev/runtime dependencies)
  • Pull request limits (per update run and/or open at any time)
  • Out-of-range updates (receive only lockfile updates, if desired)
  • Security updates (receive only security updates, if desired)

Finally, you can contact us by mentioning @dependabot.

@dependabot-preview
Copy link
Author

Superseded by #37.

@dependabot-preview dependabot-preview bot deleted the dependabot/composer/symfony/http-foundation-4.2.0 branch January 1, 2019 07:27
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant