Found 1 security vulnerability advisory affecting 1 package:
+-------------------+----------------------------------------------------------------------------------+
| Package | symfony/http-client |
| Severity | low |
| CVE | CVE-2024-50342 |
| Title | CVE-2024-50342: Internal address and port enumeration allowed by |
| | NoPrivateNetworkHttpClient |
| URL | https://symfony.com/cve-2024-50342 |
| Affected versions | >=4.3.0,<4.4.0|>=4.4.0,<5.0.0|>=5.0.0,<5.1.0|>=5.1.0,<5.2.0|>=5.2.0,<5.3.0|>=5.3 |
| | .0,<5.4.0|>=5.4.0,<5.4.47|>=6.0.0,<6.1.0|>=6.1.0,<6.2.0|>=6.2.0,<6.3.0|>=6.3.0,< |
| | 6.4.0|>=6.4.0,<6.4.15|>=7.0.0,<7.1.0|>=7.1.0,<7.1.8 |
| Reported at | 2024-11-13T08:00:00+00:00 |
+-------------------+----------------------------------------------------------------------------------+
> composer why symfony/http-client
web-token/jwt-library 3.4.7 requires symfony/http-client (^5.4|^6.0|^7.0)
> composer why web-token/jwt-library
web-token/jwt-key-mgmt 3.4.6 requires web-token/jwt-library (^3.3)
web-token/jwt-signature 3.4.6 requires web-token/jwt-library (^3.3)
web-token/jwt-signature-algorithm-ecdsa 3.4.6 requires web-token/jwt-library (^3.3)
web-token/jwt-util-ecc 3.4.6 requires web-token/jwt-library (^3.3)
> composer why web-token/jwt-key-mgmt
minishlink/web-push v7.0.0 requires web-token/jwt-key-mgmt (^2.0|^3.0.2)
> composer why minishlink/web-push
askvortsov/flarum-pwa v3.3.3 requires minishlink/web-push (^7.0)