VDB
Sign up
CRITICAL9.8

GHSA-35c5-28pg-2qg4

Symfony Authentication Bypass

Quick fix

GHSA-35c5-28pg-2qg4 — symfony/security-core: upgrade to the fixed version with the command below.

composer require symfony/security-core:^2.8.37

Details

An issue was discovered in the LDAP component in Symfony 2.8.x before 2.8.37, 3.3.x before 3.3.17, 3.4.x before 3.4.7, and 4.0.x before 4.0.7. It allows remote attackers to bypass authentication by logging in with a "null" password and valid username, which triggers an unauthenticated bind. **NOTE:** this issue exists because of an incomplete fix for CVE-2016-2403.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/symfony/security-core
Introduced in: 2.8.0Fixed in: 2.8.37
Fixcomposer require symfony/security-core:^2.8.37
Packagist/symfony/security-core
Introduced in: 3.0.0Fixed in: 3.3.17
Fixcomposer require symfony/security-core:^3.3.17
Packagist/symfony/security-core
Introduced in: 3.4.0Fixed in: 3.4.7
Fixcomposer require symfony/security-core:^3.4.7
Packagist/symfony/security-core
Introduced in: 4.0.0Fixed in: 4.0.7
Fixcomposer require symfony/security-core:^4.0.7
Packagist/symfony/security
Introduced in: 2.8.0Fixed in: 2.8.37
Fixcomposer require symfony/security:^2.8.37
Packagist/symfony/security
Introduced in: 3.0.0Fixed in: 3.3.17
Fixcomposer require symfony/security:^3.3.17
Packagist/symfony/security
Introduced in: 3.4.0Fixed in: 3.4.7
Fixcomposer require symfony/security:^3.4.7
Packagist/symfony/security
Introduced in: 4.0.0Fixed in: 4.0.7
Fixcomposer require symfony/security:^4.0.7
Packagist/symfony/symfony
Introduced in: 2.8.0Fixed in: 2.8.37
Fixcomposer require symfony/symfony:^2.8.37
Packagist/symfony/symfony
Introduced in: 3.0.0Fixed in: 3.3.17
Fixcomposer require symfony/symfony:^3.3.17
Packagist/symfony/symfony
Introduced in: 3.4.0Fixed in: 3.4.7
Fixcomposer require symfony/symfony:^3.4.7
Packagist/symfony/symfony
Introduced in: 4.0.0Fixed in: 4.0.7
Fixcomposer require symfony/symfony:^4.0.7

References