VDB
Sign up
MEDIUM5.3

GHSA-4vpc-5jx4-cfqg

User enumeration leak using switch user functionality in Symfony

Quick fix

GHSA-4vpc-5jx4-cfqg — symfony/security-http: upgrade to the fixed version with the command below.

composer require symfony/security-http:^4.2.12

Details

An issue was discovered in Symfony 4.2.0 to 4.2.11 and 4.3.0 to 4.3.7. The ability to enumerate users was possible due to different handling depending on whether the user existed when making unauthorized attempts to use the switch users functionality. This is related to symfony/security.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/symfony/security-http
Introduced in: 4.1.0Fixed in: 4.2.12
Fixcomposer require symfony/security-http:^4.2.12
Packagist/symfony/security-http
Introduced in: 4.3.0Fixed in: 4.3.8
Fixcomposer require symfony/security-http:^4.3.8
Packagist/symfony/symfony
Introduced in: 4.1.0Fixed in: 4.2.12
Fixcomposer require symfony/symfony:^4.2.12
Packagist/symfony/symfony
Introduced in: 4.3.0Fixed in: 4.3.8
Fixcomposer require symfony/symfony:^4.3.8

References