Movatterモバイル変換


[0]ホーム

URL:


Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Sign up
Appearance settings

[Security] Fix division by zero#46309

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to ourterms of service andprivacy statement. We’ll occasionally send you account related emails.

Already on GitHub?Sign in to your account

Merged
chalasr merged 1 commit intosymfony:5.4fromtvlooy:div_by_zero_in_xor
May 11, 2022
Merged

Conversation

@tvlooy
Copy link
Contributor

QA
Branch?5.4
Bug fix?yes
New feature?no
Deprecations?no
Tickets
LicenseMIT
Doc PR

Given: CSRF token abc.def.ghi was returned
When: I change the value of this token in my browser to abc..ghi
Then: the key becomes '' and the xor that is called in denormalize results in a division by zero and http 500

villers reacted with hooray emoji
@carsonbotcarsonbot added this to the5.4 milestoneMay 10, 2022
@carsonbotcarsonbot changed the titleFix division by zero[Security] Fix division by zeroMay 10, 2022
@chalasr
Copy link
Member

Good catch, thanks@tvlooy.

@chalasrchalasr merged commit5584221 intosymfony:5.4May 11, 2022
@fabpotfabpot mentioned this pull requestMay 14, 2022
This was referencedMay 27, 2022
Sign up for freeto join this conversation on GitHub. Already have an account?Sign in to comment

Reviewers

@derrabusderrabusderrabus left review comments

@nicolas-grekasnicolas-grekasnicolas-grekas approved these changes

@chalasrchalasrchalasr approved these changes

@wouterjwouterjAwaiting requested review from wouterj

Assignees

No one assigned

Projects

None yet

Milestone

5.4

Development

Successfully merging this pull request may close these issues.

5 participants

@tvlooy@chalasr@nicolas-grekas@derrabus@carsonbot

[8]ページ先頭

©2009-2025 Movatter.jp