symfony/security-core Security Advisories (5)
-
[MEDIUM] CVE-2021-21424: Prevent user enumeration via response content in authentication mechanisms
PKSA-jjrg-2n5t-nkkj CVE-2021-21424 GHSA-5pv8-ppvj-4h68
Affected version: >=2.8.0,<3.0.0|>=3.0.0,<3.1.0|>=3.1.0,<3.2.0|>=3.2.0,<3.3.0|>=3.3.0,<3.4.0|>=3.4.0,<3.4.49|>=4.0.0,<4.1.0|>=4.1.0,<4.2.0|>=4.2.0,<4.3.0|>=4.3.0,<4.4.0|>=4.4.0,<4.4.24|>=5.0.0,<5.1.0|>=5.1.0,<5.2.0|>=5.2.0,<5.2.9
Reported by:
GitHub, FriendsOfPHP/security-advisories -
[CRITICAL] CVE-2018-11407: Unauthorized access on a misconfigured LDAP server when using an empty password
PKSA-4v2q-7qd7-pgw2 CVE-2018-11407 GHSA-35c5-28pg-2qg4
Affected version: >=2.8.0,<2.8.37|>=3.0.0,<3.1.0|>=3.1.0,<3.2.0|>=3.2.0,<3.3.0|>=3.3.0,<3.3.17|>=3.4.0,<3.4.7|>=4.0.0,<4.0.7
Reported by:
GitHub, FriendsOfPHP/security-advisories -
[CRITICAL] CVE-2017-11365: Empty passwords validation issue
PKSA-2672-j1r9-dm6x CVE-2017-11365 GHSA-q87v-q8fw-gmj5
Affected version: >=2.7.30,<2.7.32|>=2.8.23,<2.8.25|>=3.2.10,<3.2.12|>=3.3.3,<3.3.5
Reported by:
GitHub, FriendsOfPHP/security-advisories -
[CRITICAL] CVE-2016-2403: Unauthorized access on a misconfigured Ldap server when using an empty password
PKSA-nz2g-y52j-n79q CVE-2016-2403 GHSA-wvj5-r78r-hhfq
Affected version: >=2.8.0,<2.8.6|>=3.0.0,<3.0.6
Reported by:
GitHub, FriendsOfPHP/security-advisories -
[HIGH] CVE-2016-1902: SecureRandom's fallback not secure when OpenSSL fails
PKSA-cdq8-87w8-19rq CVE-2016-1902 GHSA-jjx5-fq5g-8xpc
Affected version: >=2.4.0,<2.5.0|>=2.5.0,<2.6.0|>=2.6.0,<2.6.13|>=2.7.0,<2.7.9
Reported by:
GitHub, FriendsOfPHP/security-advisories