Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jxgr-3v7q-3w9v

Опубликовано: 06 нояб. 2024
Источник: github
Github: Прошло ревью
CVSS4: 2.3
CVSS3: 3.1

Описание

Symfony's Security::login does not take into account custom user_checker

Description

The custom user_checker defined on a firewall is not called when Login Programmaticaly with the Security::login method, leading to unwanted login.

Resolution

The Security::login method now ensure to call the configured user_checker.

The patch for this issue is available here for branch 6.4.

Credits

We would like to thank Oleg Andreyev, Antoine MAKDESSI for reporting the issue and Christian Flothmann for providing the fix.

Пакеты

Наименование

symfony/security-bundle

composer
Затронутые версииВерсия исправления

>= 6.2.0, < 6.4.10

6.4.10

Наименование

symfony/security-bundle

composer
Затронутые версииВерсия исправления

>= 7.0.0, < 7.0.10

7.0.10

Наименование

symfony/security-bundle

composer
Затронутые версииВерсия исправления

>= 7.1.0, < 7.1.3

7.1.3

Наименование

symfony/symfony

composer
Затронутые версииВерсия исправления

>= 6.2.0, < 6.4.10

6.4.10

Наименование

symfony/symfony

composer
Затронутые версииВерсия исправления

>= 7.0.0, < 7.0.10

7.0.10

Наименование

symfony/symfony

composer
Затронутые версииВерсия исправления

>= 7.1.0, < 7.1.3

7.1.3

EPSS

Процентиль: 33%
0.00132
Низкий

2.3 Low

CVSS4

3.1 Low

CVSS3

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 3.1
ubuntu
больше 1 года назад

symfony/security-bundle is a module for the Symphony PHP framework which provides a tight integration of the Security component into the Symfony full-stack framework. The custom `user_checker` defined on a firewall is not called when Login Programmaticaly with the `Security::login` method, leading to unwanted login. As of versions 6.4.10, 7.0.10 and 7.1.3 the `Security::login` method now ensure to call the configured `user_checker`. All users are advised to upgrade. There are no known workarounds for this vulnerability.

CVSS3: 3.1
nvd
больше 1 года назад

symfony/security-bundle is a module for the Symphony PHP framework which provides a tight integration of the Security component into the Symfony full-stack framework. The custom `user_checker` defined on a firewall is not called when Login Programmaticaly with the `Security::login` method, leading to unwanted login. As of versions 6.4.10, 7.0.10 and 7.1.3 the `Security::login` method now ensure to call the configured `user_checker`. All users are advised to upgrade. There are no known workarounds for this vulnerability.

CVSS3: 3.1
debian
больше 1 года назад

symfony/security-bundle is a module for the Symphony PHP framework whi ...

EPSS

Процентиль: 33%
0.00132
Низкий

2.3 Low

CVSS4

3.1 Low

CVSS3

Дефекты

CWE-287