Логотип exploitDog
bind:CVE-2023-46733
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-46733

Количество 5

Количество 5

ubuntu логотип

CVE-2023-46733

больше 1 года назад

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Starting in versions 5.4.21 and 6.2.7 and prior to versions 5.4.31 and 6.3.8, `SessionStrategyListener` does not migrate the session after every successful login. It does so only in case the logged in user changes by means of checking the user identifier. In some use cases, the user identifier doesn't change between the verification phase and the successful login, while the token itself changes from one type (partially-authenticated) to another (fully-authenticated). When this happens, the session id should be regenerated to prevent possible session fixations, which is not the case at the moment. As of versions 5.4.31 and 6.3.8, Symfony now checks the type of the token in addition to the user identifier before deciding whether the session id should be regenerated.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2023-46733

больше 1 года назад

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Starting in versions 5.4.21 and 6.2.7 and prior to versions 5.4.31 and 6.3.8, `SessionStrategyListener` does not migrate the session after every successful login. It does so only in case the logged in user changes by means of checking the user identifier. In some use cases, the user identifier doesn't change between the verification phase and the successful login, while the token itself changes from one type (partially-authenticated) to another (fully-authenticated). When this happens, the session id should be regenerated to prevent possible session fixations, which is not the case at the moment. As of versions 5.4.31 and 6.3.8, Symfony now checks the type of the token in addition to the user identifier before deciding whether the session id should be regenerated.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2023-46733

больше 1 года назад

Symfony is a PHP framework for web and console applications and a set ...

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-m2wj-r6g3-fxfx

больше 1 года назад

Symfony possible session fixation vulnerability

CVSS3: 6.5
EPSS: Низкий
fstec логотип

BDU:2023-08236

больше 1 года назад

Уязвимость функции SessionStrategyListener программной платформы для разработки и управления веб-приложениями Symfony, позволяющая нарушителю оказать воздействие на целостность защищаемой информации

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2023-46733

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Starting in versions 5.4.21 and 6.2.7 and prior to versions 5.4.31 and 6.3.8, `SessionStrategyListener` does not migrate the session after every successful login. It does so only in case the logged in user changes by means of checking the user identifier. In some use cases, the user identifier doesn't change between the verification phase and the successful login, while the token itself changes from one type (partially-authenticated) to another (fully-authenticated). When this happens, the session id should be regenerated to prevent possible session fixations, which is not the case at the moment. As of versions 5.4.31 and 6.3.8, Symfony now checks the type of the token in addition to the user identifier before deciding whether the session id should be regenerated.

CVSS3: 6.5
1%
Низкий
больше 1 года назад
nvd логотип
CVE-2023-46733

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Starting in versions 5.4.21 and 6.2.7 and prior to versions 5.4.31 and 6.3.8, `SessionStrategyListener` does not migrate the session after every successful login. It does so only in case the logged in user changes by means of checking the user identifier. In some use cases, the user identifier doesn't change between the verification phase and the successful login, while the token itself changes from one type (partially-authenticated) to another (fully-authenticated). When this happens, the session id should be regenerated to prevent possible session fixations, which is not the case at the moment. As of versions 5.4.31 and 6.3.8, Symfony now checks the type of the token in addition to the user identifier before deciding whether the session id should be regenerated.

CVSS3: 6.5
1%
Низкий
больше 1 года назад
debian логотип
CVE-2023-46733

Symfony is a PHP framework for web and console applications and a set ...

CVSS3: 6.5
1%
Низкий
больше 1 года назад
github логотип
GHSA-m2wj-r6g3-fxfx

Symfony possible session fixation vulnerability

CVSS3: 6.5
1%
Низкий
больше 1 года назад
fstec логотип
BDU:2023-08236

Уязвимость функции SessionStrategyListener программной платформы для разработки и управления веб-приложениями Symfony, позволяющая нарушителю оказать воздействие на целостность защищаемой информации

CVSS3: 6.5
1%
Низкий
больше 1 года назад

Уязвимостей на страницу