Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8wx3-8m4x-g5h4

Опубликовано: 15 мая 2024
Источник: github
Github: Прошло ревью

Описание

FOSUserBundle User Identity Validation Vulnerability

Versions of FOSUserBundle prior to 1.2.1 have been found to be vulnerable to a security issue related to user identity validation. Specifically, user refreshing was performed using the primary key instead of the username, leading to a potential security risk if a user is allowed to change their username. The fix in version 1.2.1 addresses this issue by loading the user using the primary key during refreshing.

Пакеты

Наименование

friendsofsymfony/user-bundle

composer
Затронутые версииВерсия исправления

>= 1.2.0, < 1.2.1

1.2.1

Дефекты

CWE-285

Дефекты

CWE-285