MEDIUM
GHSA-9mpf-g3fc-9rgv
FriendsOfSymfony FOSUserBundle denial of service via login form
Quick fix
GHSA-9mpf-g3fc-9rgv — friendsofsymfony/user-bundle: upgrade to the fixed version with the command below.
composer require friendsofsymfony/user-bundle:^1.2.5Details
The login form in the FriendsOfSymfony FOSUserBundle bundle before 1.3.3 for Symfony allows remote attackers to cause a denial of service (CPU consumption) via a long password that triggers an expensive hash computation, as demonstrated by a PBKDF2 computation.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/friendsofsymfony/user-bundle
Introduced in:
1.2.0Fixed in: 1.2.5Fix
composer require friendsofsymfony/user-bundle:^1.2.5Packagist/friendsofsymfony/user-bundle
Introduced in:
1.3.0Fixed in: 1.3.3Fix
composer require friendsofsymfony/user-bundle:^1.3.3