symfony/security-bundle is a module for the Symphony PHP framework which provides a tight integration of the Security component into the Symfony full-stack framework. The custom user_checker
defined on a firewall is not called when Login Programmaticaly with the Security::login
method, leading to unwanted login. As of versions 6.4.10, 7.0.10 and 7.1.3 the Security::login
method now ensure to call the configured user_checker
. All users are advised to upgrade. There are no known workarounds for this vulnerability.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.