Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2024-36611

Опубликовано: 29 нояб. 2024
Источник: ubuntu
Приоритет: medium
CVSS3: 7.5

Описание

In Symfony v7.07, a security vulnerability was identified in the FormLoginAuthenticator component, where it failed to adequately handle cases where the username or password field of a login request is empty. This flaw could lead to various security risks, including improper authentication logic handling or denial of service. NOTE: the Supplier has concluded that this is a false report.

РелизСтатусПримечание
devel

ignored

vulnerabilty has been disputed by upstream maintainers
esm-apps/bionic

ignored

vulnerabilty has been disputed by upstream maintainers
esm-apps/focal

ignored

vulnerabilty has been disputed by upstream maintainers
esm-apps/jammy

ignored

vulnerabilty has been disputed by upstream maintainers
esm-apps/noble

ignored

vulnerabilty has been disputed by upstream maintainers
esm-apps/xenial

ignored

vulnerabilty has been disputed by upstream maintainers
focal

ignored

end of standard support, was ignored [vulnerabilty has been disputed by upstream maintainers]
jammy

ignored

vulnerabilty has been disputed by upstream maintainers
noble

ignored

vulnerabilty has been disputed by upstream maintainers
oracular

ignored

vulnerabilty has been disputed by upstream maintainers

Показывать по

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
7 месяцев назад

In Symfony v7.07, a security vulnerability was identified in the FormLoginAuthenticator component, where it failed to adequately handle cases where the username or password field of a login request is empty. This flaw could lead to various security risks, including improper authentication logic handling or denial of service. NOTE: the Supplier has concluded that this is a false report.

CVSS3: 7.5
debian
7 месяцев назад

In Symfony v7.07, a security vulnerability was identified in the FormL ...

CVSS3: 7.5
github
7 месяцев назад

Withdrawn Advisory: Symfony http-security has authentication bypass

CVSS3: 7.5
fstec
больше 1 года назад

Уязвимость класса FormLoginAuthenticator программной платформы для разработки и управления веб-приложениями Symfony, позволяющая нарушителю обойти процедуру аутентификации и вызвать отказ в обслуживании

7.5 High

CVSS3