symfony/security-http Security Advisories (15)
-
[HIGH] CVE-2024-51996: Authentication Bypass via persisted RememberMe cookie
PKSA-rqvm-b18n-vg69 CVE-2024-51996 GHSA-cg23-qf8f-62rr
Affected version: >=5.3.0,<5.4.0|>=5.4.0,<5.4.47|>=6.0.0,<6.1.0|>=6.1.0,<6.2.0|>=6.2.0,<6.3.0|>=6.3.0,<6.4.0|>=6.4.0,<6.4.15|>=7.0.0,<7.1.0|>=7.1.0,<7.1.8
Reported by:
GitHub, FriendsOfPHP/security-advisories -
[MEDIUM] CVE-2023-46733: Possible session fixation
PKSA-5x8m-77gx-t86z CVE-2023-46733 GHSA-m2wj-r6g3-fxfx
Affected version: >=5.4.0,<5.4.31|>=6.0.0,<6.1.0|>=6.1.0,<6.2.0|>=6.2.0,<6.3.0|>=6.3.0,<6.3.8
Reported by:
GitHub, FriendsOfPHP/security-advisories -
[MEDIUM] CVE-2021-32693: Authentication granted to all firewalls instead of just one
PKSA-gg1d-f43j-pd8z CVE-2021-32693 GHSA-rfcf-m67m-jcrq
Affected version: >=5.3.0,<5.3.2
Reported by:
GitHub, FriendsOfPHP/security-advisories -
[LOW] User enumeration in authentication mechanisms
PKSA-41vr-83ph-45yn GHSA-g2qj-pmxm-9f8f
Affected version: >=5.1.0,<5.2.8
Reported by:
GitHub -
[MEDIUM] CVE-2021-21424: Prevent user enumeration via response content in authentication mechanisms
PKSA-9qm5-hby2-7bvn CVE-2021-21424 GHSA-5pv8-ppvj-4h68
Affected version: >=5.1.0,<5.2.0|>=5.2.0,<5.2.8
Reported by:
GitHub, FriendsOfPHP/security-advisories -
[HIGH] CVE-2020-5275: All rules set in "access_control" are required when the firewall is configured with the unanimous strategy
PKSA-srh1-bn3t-m6gg CVE-2020-5275 GHSA-g4m9-5hpf-hx72
Affected version: >=4.4.0,<4.4.7|>=5.0.0,<5.0.7
Reported by:
GitHub, FriendsOfPHP/security-advisories -
[MEDIUM] CVE-2019-18886: Prevent user enumeration using switch user functionality
PKSA-96vf-z7pm-9yfb CVE-2019-18886 GHSA-4vpc-5jx4-cfqg
Affected version: >=4.1.0,<4.2.0|>=4.2.0,<4.2.12|>=4.3.0,<4.3.8
Reported by:
GitHub, FriendsOfPHP/security-advisories -
[HIGH] CVE-2019-10911: Add a separator in the remember me cookie hash
PKSA-q3pf-cxf3-f7xy CVE-2019-10911 GHSA-cchx-mfrc-fwqr
Affected version: >=2.7.0,<2.7.51|>=2.8.0,<2.8.50|>=3.0.0,<3.1.0|>=3.1.0,<3.2.0|>=3.2.0,<3.3.0|>=3.3.0,<3.4.0|>=3.4.0,<3.4.26|>=4.0.0,<4.1.0|>=4.1.0,<4.1.12|>=4.2.0,<4.2.7
Reported by:
GitHub, FriendsOfPHP/security-advisories -
[MEDIUM] CVE-2018-19790: Open Redirect Vulnerability on login
PKSA-n31d-7jn4-qfx5 CVE-2018-19790 GHSA-89r2-5g34-2g47
Affected version: >=2.7.38,<2.7.50|>=2.8.0,<2.8.49|>=3.0.0,<3.1.0|>=3.1.0,<3.2.0|>=3.2.0,<3.3.0|>=3.3.0,<3.4.0|>=3.4.0,<3.4.20|>=4.0.0,<4.0.15|>=4.1.0,<4.1.9|>=4.2.0,<4.2.1
Reported by:
GitHub, FriendsOfPHP/security-advisories -
[HIGH] CVE-2018-11385: Session Fixation Issue for Guard Authentication
PKSA-r1pj-t5t2-c1n6 CVE-2018-11385 GHSA-g4rg-rw65-8hfg
Affected version: >=2.4.0,<2.7.48|>=2.5.0,<2.7.48|>=2.6.0,<2.7.48|>=2.7.0,<2.7.48|>=2.8.0,<2.8.41|>=3.0.0,<3.1.0|>=3.1.0,<3.2.0|>=3.2.0,<3.3.0|>=3.3.0,<3.3.17|>=3.4.0,<3.4.11|>=4.0.0,<4.0.11
Reported by:
GitHub, FriendsOfPHP/security-advisories -
[HIGH] CVE-2018-11406: CSRF Token Fixation
PKSA-4cs6-1fmm-cwn2 CVE-2018-11406 GHSA-g4g7-q726-v5hg
Affected version: >=2.4.0,<2.7.48|>=2.5.0,<2.7.48|>=2.6.0,<2.7.48|>=2.7.0,<2.7.48|>=2.8.0,<2.8.41|>=3.0.0,<3.1.0|>=3.1.0,<3.2.0|>=3.2.0,<3.3.0|>=3.3.0,<3.3.17|>=3.4.0,<3.4.11|>=4.0.0,<4.0.11
Reported by:
GitHub, FriendsOfPHP/security-advisories -
[MEDIUM] CVE-2017-16652: Open redirect vulnerability on security handlers
PKSA-bmrb-mr4g-zmyn CVE-2017-16652 GHSA-r7p7-qr7p-2rrf
Affected version: >=2.7.0,<2.7.38|>=2.8.0,<2.8.31|>=3.0.0,<3.1.0|>=3.1.0,<3.2.0|>=3.2.0,<3.2.14|>=3.3.0,<3.3.13
Reported by:
GitHub, FriendsOfPHP/security-advisories -
[HIGH] CVE-2016-4423: Large username storage in session
PKSA-7y48-mnc1-xvg1 CVE-2016-4423 GHSA-whgv-8cg3-7hcm
Affected version: >=2.3.0,<2.3.41|>=2.4.0,<2.5.0|>=2.5.0,<2.6.0|>=2.6.0,<2.7.0|>=2.7.0,<2.7.13|>=2.8.0,<2.8.6|>=3.0.0,<3.0.6
Reported by:
GitHub, FriendsOfPHP/security-advisories -
[LOW] CVE-2015-8124: Session Fixation in the "Remember Me" Login Feature
PKSA-m51r-2nhf-3g41 CVE-2015-8124 GHSA-j5jh-hpr4-h332
Affected version: >=2.4.0,<2.5.0|>=2.5.0,<2.6.0|>=2.6.0,<2.6.12|>=2.7.0,<2.7.7
Reported by:
GitHub, FriendsOfPHP/security-advisories -
[HIGH] CVE-2015-8125: Potential Remote Timing Attack Vulnerability in Security Remember-Me Service
PKSA-5979-1yv4-cw4f CVE-2015-8125 GHSA-g97c-jfx6-xvxh
Affected version: >=2.4.0,<2.5.0|>=2.5.0,<2.6.0|>=2.6.0,<2.6.12|>=2.7.0,<2.7.7
Reported by:
GitHub, FriendsOfPHP/security-advisories