High severity8.2NVD Advisory· Published Sep 10, 2024· Updated Jun 17, 2026
CVE-2024-45592
CVE-2024-45592
Description
auditor-bundle, formerly known as DoctrineAuditBundle, integrates auditor library into any Symfony 3.4+ application. Prior to version 5.2.6, there is an unescaped entity property enabling Javascript injection. This is possible because %source_label% in twig macro is not escaped. Therefore script tags can be inserted and are executed. The vulnerability is fixed in versions 6.0.0 and 5.2.6.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
damienharper/auditor-bundlePackagist | < 5.2.6 | 5.2.6 |
Affected products
3cpe:2.3:a:damienharper:auditor-bundle:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:damienharper:auditor-bundle:*:*:*:*:*:*:*:*range: >=5.0.0,<5.2.6
- (no CPE)range: < 5.2.6
Patches
Vulnerability mechanics
References
5- github.com/DamienHarper/auditor-bundle/commit/42ba2940d8b99467de0c806ea5655cc1c6882cd1nvdPatchWEB
- github.com/DamienHarper/auditor-bundle/commit/e7deb377fa89677d44973b486d26d6a7374233aenvdPatchWEB
- github.com/DamienHarper/auditor-bundle/security/advisories/GHSA-78vg-7v27-hj67nvdVendor AdvisoryWEB
- github.com/advisories/GHSA-78vg-7v27-hj67ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-45592ghsaADVISORY
News mentions
0No linked articles in our index yet.