Описание
Symfony Authentication Bypass
Symfony before 2.8.6 and 3.x before 3.0.6 allows remote attackers to bypass authentication by logging in with an empty password and valid username, which triggers an unauthenticated bind.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2016-2403
- https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/security-core/CVE-2016-2403.yaml
- https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/security/CVE-2016-2403.yaml
- https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/symfony/CVE-2016-2403.yaml
- https://symfony.com/cve-2016-2403
- https://web.archive.org/web/20210123224944/http://www.securityfocus.com/bid/96137
- https://www.debian.org/security/2018/dsa-4262
- http://symfony.com/blog/cve-2016-2403-unauthorized-access-on-a-misconfigured-ldap-server-when-using-an-empty-password
Пакеты
symfony/security-core
>= 2.8.0, < 2.8.6
2.8.6
symfony/security-core
>= 3.0.0, < 3.0.6
3.0.6
symfony/security
>= 2.8.0, < 2.8.6
2.8.6
symfony/security
>= 3.0.0, < 3.0.6
3.0.6
symfony/symfony
>= 2.8.0, < 2.8.6
2.8.6
symfony/symfony
>= 3.0.0, < 3.0.6
3.0.6
Связанные уязвимости
Symfony before 2.8.6 and 3.x before 3.0.6 allows remote attackers to bypass authentication by logging in with an empty password and valid username, which triggers an unauthenticated bind.
Symfony before 2.8.6 and 3.x before 3.0.6 allows remote attackers to bypass authentication by logging in with an empty password and valid username, which triggers an unauthenticated bind.
Symfony before 2.8.6 and 3.x before 3.0.6 allows remote attackers to b ...
Уязвимость программной платформы для разработки и управления веб-приложениями Symfony, связанная с ошибками обработки авторизационных данных пользователей, позволяющая нарушителю обойти процедуру аутентификации