CRITICAL9.8
GHSA-35c5-28pg-2qg4
Symfony Authentication Bypass
Quick fix
GHSA-35c5-28pg-2qg4 — symfony/security-core: upgrade to the fixed version with the command below.
composer require symfony/security-core:^2.8.37Details
An issue was discovered in the LDAP component in Symfony 2.8.x before 2.8.37, 3.3.x before 3.3.17, 3.4.x before 3.4.7, and 4.0.x before 4.0.7. It allows remote attackers to bypass authentication by logging in with a "null" password and valid username, which triggers an unauthenticated bind. **NOTE:** this issue exists because of an incomplete fix for CVE-2016-2403.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/symfony/security-core
Introduced in:
2.8.0Fixed in: 2.8.37Fix
composer require symfony/security-core:^2.8.37Packagist/symfony/security-core
Introduced in:
3.0.0Fixed in: 3.3.17Fix
composer require symfony/security-core:^3.3.17Packagist/symfony/security-core
Introduced in:
3.4.0Fixed in: 3.4.7Fix
composer require symfony/security-core:^3.4.7Packagist/symfony/security-core
Introduced in:
4.0.0Fixed in: 4.0.7Fix
composer require symfony/security-core:^4.0.7Packagist/symfony/security
Introduced in:
2.8.0Fixed in: 2.8.37Fix
composer require symfony/security:^2.8.37Packagist/symfony/security
Introduced in:
3.0.0Fixed in: 3.3.17Fix
composer require symfony/security:^3.3.17Packagist/symfony/security
Introduced in:
3.4.0Fixed in: 3.4.7Fix
composer require symfony/security:^3.4.7Packagist/symfony/security
Introduced in:
4.0.0Fixed in: 4.0.7Fix
composer require symfony/security:^4.0.7Packagist/symfony/symfony
Introduced in:
2.8.0Fixed in: 2.8.37Fix
composer require symfony/symfony:^2.8.37Packagist/symfony/symfony
Introduced in:
3.0.0Fixed in: 3.3.17Fix
composer require symfony/symfony:^3.3.17Packagist/symfony/symfony
Introduced in:
3.4.0Fixed in: 3.4.7Fix
composer require symfony/symfony:^3.4.7Packagist/symfony/symfony
Introduced in:
4.0.0Fixed in: 4.0.7Fix
composer require symfony/symfony:^4.0.7References
- https://nvd.nist.gov/vuln/detail/CVE-2018-11407[ADVISORY]
- https://github.com/symfony/symfony/pull/27377[WEB]
- https://github.com/symfony/symfony/commit/b46fc93785d37ffa5d706a82cd175b33ce8f2934[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/security-core/CVE-2018-11407.yaml[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/security/CVE-2018-11407.yaml[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/symfony/CVE-2018-11407.yaml[WEB]
- https://github.com/symfony/symfony[PACKAGE]
- https://symfony.com/blog/cve-2018-11407-unauthorized-access-on-a-misconfigured-ldap-server-when-using-an-empty-password[WEB]
- https://symfony.com/cve-2018-11407[WEB]