--------------------------------------------------------------------------------Fedora Update Notification
FEDORA-2021-2d145b95f6
2021-05-29 01:04:01.502352
--------------------------------------------------------------------------------Name        : php-symfony4
Product     : Fedora 34
Version     : 4.4.24
Release     : 1.fc34
URL         : https://symfony.com
Summary     : Symfony PHP framework (version 4)
Description :
Symfony PHP framework (version 4).

NOTE: Does not require PHPUnit bridge.

--------------------------------------------------------------------------------Update Information:

**Version  4.4.24** (2021-05-19)   * security **CVE-2021-21424** [Security\Core]
Fix user enumeration via response body on invalid credentials (chalasr)  * bug
#41230 [FrameworkBundle][Validator] Fix deprecations from Doctrine
Annotations+Cache (derrabus)  * bug #41240 Fixed deprecation warnings about
passing null as parameter (derrabus)  * bug #41241 [Finder] Fix gitignore regex
build with "**" (mvorisek)  * bug #41224 [HttpClient] fix adding query string to
relative URLs with scoped clients (nicolas-grekas)  * bug #41233
[DependencyInjection][ProxyManagerBridge] Don't call class_exists() on null
(derrabus)  * bug #41210 [Console] Fix Windows code page support (orkan)    ----**Version  4.4.23** (2021-05-12)   * security **CVE-2021-21424**
[Security][Guard] Prevent user enumeration (chalasr)  * bug #41176
[DependencyInjection] fix dumping service-closure-arguments (nicolas-grekas)  *
bug #41168 WDT: Only load "Sfjs" if it is not present already (weaverryan)  *
bug #41147 [Inflector][String] wrong plural form of words ending by "pectus"
(makraz)  * bug #41160 [HttpClient] Don't prepare the request in
ScopingHttpClient (nicolas-grekas)  * bug #40763 Fix/Rewrite .gitignore regex
builder (mvorisek)  * bug #40917 [Config][DependencyInjection] Uniformize
trailing slash handling (dunglas)  * bug #40699 [PropertyInfo] Make
ReflectionExtractor correctly extract nullability (shiftby)  * bug #40874
[PropertyInfo] fix attribute namespace with recursive traits (soullivaneuh)  *
bug #41099 [Cache] Check if phpredis version is compatible with stream parameter
(nicolassing)  * bug #41072 [VarExporter] Add support of PHP enumerations
(alexandre-daubois)  * bug #41105 [Inflector][String] Fixed singularize `edges`
> `edge` (ruudk)  * bug #41075 [ErrorHandler] Skip "same vendor" ``@method``
deprecations for `Symfony\*` classes unless symfony/symfony is being tested
(nicolas-grekas)
--------------------------------------------------------------------------------ChangeLog:

* Wed May 19 2021 Remi Collet  - 4.4.24-1
- update to 4.4.24
* Mon May 17 2021 Remi Collet  - 4.4.23-1
- update to 4.4.23
--------------------------------------------------------------------------------References:

  [ 1 ] Bug #1960631 - CVE-2021-21424 php-symfony: user enumeration in authentication mechanisms [fedora-all]
        https://bugzilla.redhat.com/show_bug.cgi?id=1960631
--------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2021-2d145b95f6' at the command
line. For more information, refer to the dnf documentation available at
https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/security/
--------------------------------------------------------------------------------_______________________________________________
package-announce mailing list -- package-announce@lists.fedoraproject.org
To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/
Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure

Fedora 34: php-symfony4 2021-2d145b95f6

May 28, 2021
**Version 4.4.24** (2021-05-19) * security **CVE-2021-21424** [Security\Core] Fix user enumeration via response body on invalid credentials (chalasr) * bug #41230 [FrameworkBundle...

Summary

Symfony PHP framework (version 4).

NOTE: Does not require PHPUnit bridge.

**Version 4.4.24** (2021-05-19) * security **CVE-2021-21424** [Security\Core]

Fix user enumeration via response body on invalid credentials (chalasr) * bug

#41230 [FrameworkBundle][Validator] Fix deprecations from Doctrine

Annotations+Cache (derrabus) * bug #41240 Fixed deprecation warnings about

passing null as parameter (derrabus) * bug #41241 [Finder] Fix gitignore regex

build with "**" (mvorisek) * bug #41224 [HttpClient] fix adding query string to

relative URLs with scoped clients (nicolas-grekas) * bug #41233

[DependencyInjection][ProxyManagerBridge] Don't call class_exists() on null

(derrabus) * bug #41210 [Console] Fix Windows code page support (orkan) ----**Version 4.4.23** (2021-05-12) * security **CVE-2021-21424**

[Security][Guard] Prevent user enumeration (chalasr) * bug #41176

[DependencyInjection] fix dumping service-closure-arguments (nicolas-grekas) *

bug #41168 WDT: Only load "Sfjs" if it is not present already (weaverryan) *

bug #41147 [Inflector][String] wrong plural form of words ending by "pectus"

(makraz) * bug #41160 [HttpClient] Don't prepare the request in

ScopingHttpClient (nicolas-grekas) * bug #40763 Fix/Rewrite .gitignore regex

builder (mvorisek) * bug #40917 [Config][DependencyInjection] Uniformize

trailing slash handling (dunglas) * bug #40699 [PropertyInfo] Make

ReflectionExtractor correctly extract nullability (shiftby) * bug #40874

[PropertyInfo] fix attribute namespace with recursive traits (soullivaneuh) *

bug #41099 [Cache] Check if phpredis version is compatible with stream parameter

(nicolassing) * bug #41072 [VarExporter] Add support of PHP enumerations

(alexandre-daubois) * bug #41105 [Inflector][String] Fixed singularize `edges`

> `edge` (ruudk) * bug #41075 [ErrorHandler] Skip "same vendor" ``@method``

deprecations for `Symfony\*` classes unless symfony/symfony is being tested

(nicolas-grekas)

* Wed May 19 2021 Remi Collet - 4.4.24-1

- update to 4.4.24

* Mon May 17 2021 Remi Collet - 4.4.23-1

- update to 4.4.23

[ 1 ] Bug #1960631 - CVE-2021-21424 php-symfony: user enumeration in authentication mechanisms [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1960631

su -c 'dnf upgrade --advisory FEDORA-2021-2d145b95f6' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure

FEDORA-2021-2d145b95f6 2021-05-29 01:04:01.502352 Product : Fedora 34 Version : 4.4.24 Release : 1.fc34 URL : https://symfony.com Summary : Symfony PHP framework (version 4) Description : Symfony PHP framework (version 4). NOTE: Does not require PHPUnit bridge. **Version 4.4.24** (2021-05-19) * security **CVE-2021-21424** [Security\Core] Fix user enumeration via response body on invalid credentials (chalasr) * bug #41230 [FrameworkBundle][Validator] Fix deprecations from Doctrine Annotations+Cache (derrabus) * bug #41240 Fixed deprecation warnings about passing null as parameter (derrabus) * bug #41241 [Finder] Fix gitignore regex build with "**" (mvorisek) * bug #41224 [HttpClient] fix adding query string to relative URLs with scoped clients (nicolas-grekas) * bug #41233 [DependencyInjection][ProxyManagerBridge] Don't call class_exists() on null (derrabus) * bug #41210 [Console] Fix Windows code page support (orkan) ----**Version 4.4.23** (2021-05-12) * security **CVE-2021-21424** [Security][Guard] Prevent user enumeration (chalasr) * bug #41176 [DependencyInjection] fix dumping service-closure-arguments (nicolas-grekas) * bug #41168 WDT: Only load "Sfjs" if it is not present already (weaverryan) * bug #41147 [Inflector][String] wrong plural form of words ending by "pectus" (makraz) * bug #41160 [HttpClient] Don't prepare the request in ScopingHttpClient (nicolas-grekas) * bug #40763 Fix/Rewrite .gitignore regex builder (mvorisek) * bug #40917 [Config][DependencyInjection] Uniformize trailing slash handling (dunglas) * bug #40699 [PropertyInfo] Make ReflectionExtractor correctly extract nullability (shiftby) * bug #40874 [PropertyInfo] fix attribute namespace with recursive traits (soullivaneuh) * bug #41099 [Cache] Check if phpredis version is compatible with stream parameter (nicolassing) * bug #41072 [VarExporter] Add support of PHP enumerations (alexandre-daubois) * bug #41105 [Inflector][String] Fixed singularize `edges` > `edge` (ruudk) * bug #41075 [ErrorHandler] Skip "same vendor" ``@method`` deprecations for `Symfony\*` classes unless symfony/symfony is being tested (nicolas-grekas) * Wed May 19 2021 Remi Collet - 4.4.24-1 - update to 4.4.24 * Mon May 17 2021 Remi Collet - 4.4.23-1 - update to 4.4.23 [ 1 ] Bug #1960631 - CVE-2021-21424 php-symfony: user enumeration in authentication mechanisms [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1960631 su -c 'dnf upgrade --advisory FEDORA-2021-2d145b95f6' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ package-announce mailing list -- package-announce@lists.fedoraproject.org To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/ Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure

Change Log

References

Update Instructions

Severity
Product : Fedora 34
Version : 4.4.24
Release : 1.fc34
URL : https://symfony.com
Summary : Symfony PHP framework (version 4)

Related News