Affected versions: ibexa/templated-uri-bundle v2.1.*, v3.3.*
Resolving versions: ibexa/templated-uri-bundle v22.214.171.124, v126.96.36.199
This security advisory is about a vulnerability in Symfony where validation messages are not escaped, which can lead to XSS when user input is included. There is no known exploit against Ibexa software, but we recommend applying the fix.
The issue is fixed in symfony/framework-bundle 2.8.50, 3.4.26, 4.1.12, and 4.2.7.
The Ibexa package ibexa/templated-uri-bundle requires these versions since v188.8.131.52 (eZ Platform v2.5), and v184.108.40.206 (Ibexa DXP v3.3 and v4).
Have you found a security bug in Ibexa DXP? See how to report it responsibly here: https://doc.ibexa.co/en/latest/guide/reporting_issues/