VDB
Sign up
HIGH7.5

GHSA-cg23-qf8f-62rr

Symfony has an Authentication Bypass via RememberMe

Quick fix

GHSA-cg23-qf8f-62rr — symfony/security-http: upgrade to the fixed version with the command below.

composer require symfony/security-http:^5.4.47

Details

### Description

When consuming a persisted remember-me cookie, Symfony does not check if the username persisted in the database matches the username attached with the cookie, leading to authentication bypass.

### Resolution

The `PersistentRememberMeHandler` class now ensures the submitted username is the cookie owner.

The patch for this issue is available [here](https://github.com/symfony/symfony/commit/81354d392c5f0b7a52bcbd729d6f82501e94135a) for branch 5.4.

### Credits

We would like to thank Moritz Rauch - Pentryx AG for reporting the issue and Jérémy Derussé for providing the fix.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/symfony/security-http
Introduced in: 5.3.0Fixed in: 5.4.47
Fixcomposer require symfony/security-http:^5.4.47
Packagist/symfony/security-http
Introduced in: 6.0.0-BETA1Fixed in: 6.4.15
Fixcomposer require symfony/security-http:^6.4.15
Packagist/symfony/security-http
Introduced in: 7.0.0-BETA1Fixed in: 7.1.8
Fixcomposer require symfony/security-http:^7.1.8

References