CVE Vulnerabilities

CVE-2024-51996

Improper Authentication

Published: Nov 13, 2024 | Modified: Nov 15, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Symphony process is a module for the Symphony PHP framework which executes commands in sub-processes. When consuming a persisted remember-me cookie, Symfony does not check if the username persisted in the database matches the username attached with the cookie, leading to authentication bypass. This vulnerability is fixed in 5.4.47, 6.4.15, and 7.1.8.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

NameVendorStart VersionEnd Version
SymfonyUbuntuesm-apps/jammy*
SymfonyUbuntuesm-apps/noble*
SymfonyUbuntufocal*
SymfonyUbuntunoble*
SymfonyUbuntuoracular*
SymfonyUbuntuplucky*
SymfonyUbuntuupstream*

Potential Mitigations

References