In symfony/security-http before versions 4.4.7 and 5.0.7, when a `Firewall` checks access control rule, it iterate overs each rule's attributes and stops as soon as the accessDecisionManager decides to grant access on the attribute, preventing the check of next attributes that should have been take into account in an unanimous strategy.
Upstream Reference: https://github.com/symfony/symfony/security/advisories/GHSA-g4m9-5hpf-hx72
Created php-symfony4 tracking bugs for this issue: Affects: fedora-all [bug 1820555]
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.