Описание
Symphony process is a module for the Symphony PHP framework which executes commands in sub-processes. When consuming a persisted remember-me cookie, Symfony does not check if the username persisted in the database matches the username attached with the cookie, leading to authentication bypass. This vulnerability is fixed in 5.4.47, 6.4.15, and 7.1.8.
Релиз | Статус | Примечание |
---|---|---|
devel | needs-triage | |
esm-apps/bionic | not-affected | code not present |
esm-apps/focal | not-affected | code not present |
esm-apps/jammy | ignored | not feasible to fix |
esm-apps/noble | released | 6.4.5+dfsg-3ubuntu3+esm1 |
esm-apps/xenial | not-affected | code not present |
focal | ignored | end of standard support, was needs-triage |
jammy | needs-triage | |
noble | needed | |
oracular | needs-triage |
Показывать по
Ссылки на источники
EPSS
7.5 High
CVSS3
Связанные уязвимости
Symphony process is a module for the Symphony PHP framework which executes commands in sub-processes. When consuming a persisted remember-me cookie, Symfony does not check if the username persisted in the database matches the username attached with the cookie, leading to authentication bypass. This vulnerability is fixed in 5.4.47, 6.4.15, and 7.1.8.
Symphony process is a module for the Symphony PHP framework which exec ...
Symfony has an Authentication Bypass via RememberMe
Уязвимость компонента Process программной платформы для разработки и управления веб-приложениями Symfony, позволяющая нарушителю обойти ограничения безопасности
EPSS
7.5 High
CVSS3