CVE Vulnerabilities

CVE-2015-8125

Published: Dec 07, 2015 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Symfony 2.3.x before 2.3.35, 2.6.x before 2.6.12, and 2.7.x before 2.7.7 might allow remote attackers to have unspecified impact via a timing attack involving the (1) Symfony/Component/Security/Http/RememberMe/PersistentTokenBasedRememberMeServices or (2) Symfony/Component/Security/Http/Firewall/DigestAuthenticationListener class in the Symfony Security Component, or (3) legacy CSRF implementation from the Symfony/Component/Form/Extension/Csrf/CsrfProvider/DefaultCsrfProvider class in the Symfony Form component.

Affected Software

NameVendorStart VersionEnd Version
SymfonySensiolabs2.3.0 (including)2.3.0 (including)
SymfonySensiolabs2.3.1 (including)2.3.1 (including)
SymfonySensiolabs2.3.2 (including)2.3.2 (including)
SymfonySensiolabs2.3.3 (including)2.3.3 (including)
SymfonySensiolabs2.3.4 (including)2.3.4 (including)
SymfonySensiolabs2.3.5 (including)2.3.5 (including)
SymfonySensiolabs2.3.6 (including)2.3.6 (including)
SymfonySensiolabs2.3.7 (including)2.3.7 (including)
SymfonySensiolabs2.3.8 (including)2.3.8 (including)
SymfonySensiolabs2.3.9 (including)2.3.9 (including)
SymfonySensiolabs2.3.10 (including)2.3.10 (including)
SymfonySensiolabs2.3.11 (including)2.3.11 (including)
SymfonySensiolabs2.3.12 (including)2.3.12 (including)
SymfonySensiolabs2.3.13 (including)2.3.13 (including)
SymfonySensiolabs2.3.14 (including)2.3.14 (including)
SymfonySensiolabs2.3.15 (including)2.3.15 (including)
SymfonySensiolabs2.3.16 (including)2.3.16 (including)
SymfonySensiolabs2.3.17 (including)2.3.17 (including)
SymfonySensiolabs2.3.18 (including)2.3.18 (including)
SymfonySensiolabs2.3.19 (including)2.3.19 (including)
SymfonySensiolabs2.3.20 (including)2.3.20 (including)
SymfonySensiolabs2.3.21 (including)2.3.21 (including)
SymfonySensiolabs2.3.22 (including)2.3.22 (including)
SymfonySensiolabs2.3.23 (including)2.3.23 (including)
SymfonySensiolabs2.3.24 (including)2.3.24 (including)
SymfonySensiolabs2.3.25 (including)2.3.25 (including)
SymfonySensiolabs2.3.26 (including)2.3.26 (including)
SymfonySensiolabs2.3.27 (including)2.3.27 (including)
SymfonySensiolabs2.3.28 (including)2.3.28 (including)
SymfonySensiolabs2.3.29 (including)2.3.29 (including)
SymfonySensiolabs2.3.30 (including)2.3.30 (including)
SymfonySensiolabs2.3.31 (including)2.3.31 (including)
SymfonySensiolabs2.3.32 (including)2.3.32 (including)
SymfonySensiolabs2.3.33 (including)2.3.33 (including)
SymfonySensiolabs2.3.34 (including)2.3.34 (including)
SymfonySensiolabs2.6.0 (including)2.6.0 (including)
SymfonySensiolabs2.6.1 (including)2.6.1 (including)
SymfonySensiolabs2.6.2 (including)2.6.2 (including)
SymfonySensiolabs2.6.3 (including)2.6.3 (including)
SymfonySensiolabs2.6.4 (including)2.6.4 (including)
SymfonySensiolabs2.6.5 (including)2.6.5 (including)
SymfonySensiolabs2.6.6 (including)2.6.6 (including)
SymfonySensiolabs2.6.7 (including)2.6.7 (including)
SymfonySensiolabs2.6.8 (including)2.6.8 (including)
SymfonySensiolabs2.6.9 (including)2.6.9 (including)
SymfonySensiolabs2.6.10 (including)2.6.10 (including)
SymfonySensiolabs2.6.11 (including)2.6.11 (including)
SymfonySensiolabs2.7.0 (including)2.7.0 (including)
SymfonySensiolabs2.7.1 (including)2.7.1 (including)
SymfonySensiolabs2.7.2 (including)2.7.2 (including)
SymfonySensiolabs2.7.3 (including)2.7.3 (including)
SymfonySensiolabs2.7.4 (including)2.7.4 (including)
SymfonySensiolabs2.7.5 (including)2.7.5 (including)
SymfonySensiolabs2.7.6 (including)2.7.6 (including)
SymfonyUbuntuartful*
SymfonyUbuntuupstream*
SymfonyUbuntuvivid*
SymfonyUbuntuwily*
SymfonyUbuntuyakkety*
SymfonyUbuntuzesty*

References