Symfony Security Check Report
=============================
4 packages have known vulnerabilities.
facade/ignition (2.0.2)
-----------------------
* [CVE-2021-3129][]: Remote code execution
laravel/framework (v7.10.3)
---------------------------
* [CVE-NONE-0001][]: RCE vulnerability in "cookie" session driver
* [CVE-NONE-0002][]: Guard bypass in Eloquent models
* [CVE-NONE-0003][]: Unexpected bindings in QueryBuilder
* [CVE-NONE-0004][]: SQL Server LIMIT / OFFSET SQL Injection
* [CVE-2021-21263][]: Unexpected bindings in QueryBuilder
phpoffice/phpspreadsheet (1.12.0)
---------------------------------
* [CVE-2020-7776][]: XSS Vulnerability in HTML Writer
symfony/http-kernel (v5.0.8)
----------------------------
* [CVE-2020-15094][]: Prevent RCE when calling untrusted remote with CachingHttpClient
[CVE-2021-3129]:
https://github.com/facade/ignition/pull/334[CVE-NONE-0001]:
https://blog.laravel.com/laravel-cookie-security-releases[CVE-NONE-0002]:
https://blog.laravel.com/security-release-laravel-61834-7232[CVE-NONE-0003]:
https://github.com/laravel/framework/security/advisories/GHSA-x7p5-p2c9-phvg[CVE-NONE-0004]:
https://github.com/laravel/framework/security/advisories/GHSA-4mg9-vhxq-vm7j[CVE-2021-21263]:
https://blog.laravel.com/security-laravel-62011-7302-8221-released[CVE-2020-7776]:
https://github.com/PHPOffice/PhpSpreadsheet/pull/1719[CVE-2020-15094]:
https://symfony.com/cve-2020-15094