CRITICAL9.8
GHSA-wvj5-r78r-hhfq
Symfony Authentication Bypass
Quick fix
GHSA-wvj5-r78r-hhfq — symfony/security-core: upgrade to the fixed version with the command below.
composer require symfony/security-core:^2.8.6Details
Symfony before 2.8.6 and 3.x before 3.0.6 allows remote attackers to bypass authentication by logging in with an empty password and valid username, which triggers an unauthenticated bind.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/symfony/security-core
Introduced in:
2.8.0Fixed in: 2.8.6Fix
composer require symfony/security-core:^2.8.6Packagist/symfony/security-core
Introduced in:
3.0.0Fixed in: 3.0.6Fix
composer require symfony/security-core:^3.0.6Packagist/symfony/security
Introduced in:
2.8.0Fixed in: 2.8.6Fix
composer require symfony/security:^2.8.6Packagist/symfony/security
Introduced in:
3.0.0Fixed in: 3.0.6Fix
composer require symfony/security:^3.0.6Packagist/symfony/symfony
Introduced in:
2.8.0Fixed in: 2.8.6Fix
composer require symfony/symfony:^2.8.6Packagist/symfony/symfony
Introduced in:
3.0.0Fixed in: 3.0.6Fix
composer require symfony/symfony:^3.0.6References
- https://nvd.nist.gov/vuln/detail/CVE-2016-2403[ADVISORY]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/security-core/CVE-2016-2403.yaml[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/security/CVE-2016-2403.yaml[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/symfony/CVE-2016-2403.yaml[WEB]
- https://symfony.com/cve-2016-2403[WEB]
- https://web.archive.org/web/20210123224944/http://www.securityfocus.com/bid/96137[WEB]
- https://www.debian.org/security/2018/dsa-4262[WEB]
- http://symfony.com/blog/cve-2016-2403-unauthorized-access-on-a-misconfigured-ldap-server-when-using-an-empty-password[WEB]