GHSA-jxgr-3v7q-3w9v
Symfony's `Security::login` does not take into account custom `user_checker`
Quick fix
GHSA-jxgr-3v7q-3w9v — symfony/security-bundle: upgrade to the fixed version with the command below.
composer require symfony/security-bundle:^6.4.10Details
### Description
The custom `user_checker` defined on a firewall is not called when Login Programmaticaly with the `Security::login` method, leading to unwanted login.
### Resolution
The `Security::login` method now ensure to call the configured `user_checker`.
The patch for this issue is available [here](https://github.com/symfony/symfony/commit/22a0789a0085c3ee96f4ef715ecad8255cf0e105) for branch 6.4.
### Credits
We would like to thank Oleg Andreyev, Antoine MAKDESSI for reporting the issue and Christian Flothmann for providing the fix.
Are you affected?
Enter the version of the package you're using.
Affected packages
6.2.0Fixed in: 6.4.10composer require symfony/security-bundle:^6.4.107.0.0Fixed in: 7.0.10composer require symfony/security-bundle:^7.0.107.1.0Fixed in: 7.1.3composer require symfony/security-bundle:^7.1.36.2.0Fixed in: 6.4.10composer require symfony/symfony:^6.4.107.0.0Fixed in: 7.0.10composer require symfony/symfony:^7.0.107.1.0Fixed in: 7.1.3composer require symfony/symfony:^7.1.3References
- https://github.com/symfony/symfony/security/advisories/GHSA-jxgr-3v7q-3w9v[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2024-50341[ADVISORY]
- https://github.com/symfony/symfony/commit/22a0789a0085c3ee96f4ef715ecad8255cf0e105[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/security-bundle/CVE-2024-50341.yaml[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/symfony/CVE-2024-50341.yaml[WEB]
- https://github.com/symfony/symfony[PACKAGE]
- https://symfony.com/cve-2024-50341[WEB]