An issue was discovered in Symfony 2.8.0 through 2.8.50, 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4.3.7. The UriSigner was subject to timing attacks. This is related to symfony/http-kernel.
{
"versions": [
{
"introduced": "2.8.0"
},
{
"last_affected": "2.8.50"
},
{
"introduced": "3.4.0"
},
{
"last_affected": "3.4.34"
},
{
"introduced": "4.2.0"
},
{
"last_affected": "4.2.11"
},
{
"introduced": "4.3.0"
},
{
"last_affected": "4.3.7"
}
]
}