In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, a vulnerability would allow an attacker to authenticate as a privileged user on sites with user registration and remember me login functionality enabled. This is related to symfony/security.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Symfony | Sensiolabs | 2.7.0 (including) | 2.7.51 (excluding) |
Symfony | Sensiolabs | 2.8.0 (including) | 2.8.50 (excluding) |
Symfony | Sensiolabs | 3.4.0 (including) | 3.4.26 (excluding) |
Symfony | Sensiolabs | 4.1.0 (including) | 4.1.12 (excluding) |
Symfony | Sensiolabs | 4.2.0 (including) | 4.2.7 (excluding) |
Symfony | Ubuntu | bionic | * |
Symfony | Ubuntu | cosmic | * |
Symfony | Ubuntu | disco | * |
Symfony | Ubuntu | esm-apps/bionic | * |
Symfony | Ubuntu | esm-apps/xenial | * |
Symfony | Ubuntu | upstream | * |
Symfony | Ubuntu | xenial | * |