[GHSA-cg28-v4wq-whv5] Symfony's VarDumper vulnerable to unsafe deserialization #5048
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Updates
Comments
Similar to #5046 about GHSA-7q22-x757-cmgc reported by the same user, there is no vulnerability
We just discovered this advisory, and after investigation, we found that this is a false report.
Their is no such vulnerability, and the link to the patch is not related to any vulnerability fix.
Looks like someone created hundred of false CVE https://gist.github.com/1047524396 : all CVE registered in MITR have a backlink to the a gist created by this user