The issue was attempted to be solved in https://github.com/symfony/symfony/commit/c72537da6b906d9d7599a0ce00aead597804d0c7 but as far as I can see it still does not cary the requirements to the locale parameter. Thus everyting could be used as locale and the locale prefixed routes might match tings that it should not.
Regards Ivar -- If you want to report a vulnerability issue on symfony, please send it to security at symfony-project.com You received this message because you are subscribed to the Google Groups "symfony developers" group. To post to this group, send email to [email protected] To unsubscribe from this group, send email to [email protected] For more options, visit this group at http://groups.google.com/group/symfony-devs?hl=en
