MEDIUM5.3
GHSA-4vpc-5jx4-cfqg
User enumeration leak using switch user functionality in Symfony
Quick fix
GHSA-4vpc-5jx4-cfqg — symfony/security-http: upgrade to the fixed version with the command below.
composer require symfony/security-http:^4.2.12Details
An issue was discovered in Symfony 4.2.0 to 4.2.11 and 4.3.0 to 4.3.7. The ability to enumerate users was possible due to different handling depending on whether the user existed when making unauthorized attempts to use the switch users functionality. This is related to symfony/security.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/symfony/security-http
Introduced in:
4.1.0Fixed in: 4.2.12Fix
composer require symfony/security-http:^4.2.12Packagist/symfony/security-http
Introduced in:
4.3.0Fixed in: 4.3.8Fix
composer require symfony/security-http:^4.3.8Packagist/symfony/symfony
Introduced in:
4.1.0Fixed in: 4.2.12Fix
composer require symfony/symfony:^4.2.12Packagist/symfony/symfony
Introduced in:
4.3.0Fixed in: 4.3.8Fix
composer require symfony/symfony:^4.3.8References
- https://nvd.nist.gov/vuln/detail/CVE-2019-18886[ADVISORY]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/security-http/CVE-2019-18886.yaml[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/symfony/CVE-2019-18886.yaml[WEB]
- https://github.com/symfony/symfony/releases/tag/v4.3.8[WEB]
- https://symfony.com/blog/cve-2019-18886-prevent-user-enumeration-using-switch-user-functionality[WEB]
- https://symfony.com/blog/symfony-4-3-8-released[WEB]
- https://symfony.com/cve-2019-18886[WEB]