Описание
Symfony 2.3.x before 2.3.35, 2.6.x before 2.6.12, and 2.7.x before 2.7.7 might allow remote attackers to have unspecified impact via a timing attack involving the (1) Symfony/Component/Security/Http/RememberMe/PersistentTokenBasedRememberMeServices or (2) Symfony/Component/Security/Http/Firewall/DigestAuthenticationListener class in the Symfony Security Component, or (3) legacy CSRF implementation from the Symfony/Component/Form/Extension/Csrf/CsrfProvider/DefaultCsrfProvider class in the Symfony Form component.
| Релиз | Статус | Примечание | 
|---|---|---|
| artful | ignored  | end of life | 
| bionic | not-affected  | 3.4.6+dfsg-1 | 
| devel | not-affected  | 3.4.15+dfsg-2ubuntu4 | 
| esm-apps/bionic | not-affected  | 3.4.6+dfsg-1 | 
| esm-apps/xenial | not-affected  | 2.7.10-0ubuntu2 | 
| esm-infra-legacy/trusty | DNE  | |
| precise | DNE  | |
| precise/esm | DNE  | |
| trusty | DNE  | |
| trusty/esm | DNE  | 
Показывать по
EPSS
7.5 High
CVSS2
Связанные уязвимости
Symfony 2.3.x before 2.3.35, 2.6.x before 2.6.12, and 2.7.x before 2.7.7 might allow remote attackers to have unspecified impact via a timing attack involving the (1) Symfony/Component/Security/Http/RememberMe/PersistentTokenBasedRememberMeServices or (2) Symfony/Component/Security/Http/Firewall/DigestAuthenticationListener class in the Symfony Security Component, or (3) legacy CSRF implementation from the Symfony/Component/Form/Extension/Csrf/CsrfProvider/DefaultCsrfProvider class in the Symfony Form component.
Symfony 2.3.x before 2.3.35, 2.6.x before 2.6.12, and 2.7.x before 2.7 ...
EPSS
7.5 High
CVSS2