Логотип exploitDog
bind:CVE-2021-21424
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-21424

Количество 5

Количество 5

ubuntu логотип

CVE-2021-21424

около 4 лет назад

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. The ability to enumerate users was possible without relevant permissions due to different handling depending on whether the user existed or not when attempting to use the switch users functionality. We now ensure that 403s are returned whether the user exists or not if a user cannot switch to a user or if the user does not exist. The patch for this issue is available for branch 3.4.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2021-21424

около 4 лет назад

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. The ability to enumerate users was possible without relevant permissions due to different handling depending on whether the user existed or not when attempting to use the switch users functionality. We now ensure that 403s are returned whether the user exists or not if a user cannot switch to a user or if the user does not exist. The patch for this issue is available for branch 3.4.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2021-21424

около 4 лет назад

Symfony is a PHP framework for web and console applications and a set ...

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-5pv8-ppvj-4h68

около 4 лет назад

Prevent user enumeration using Guard or the new Authenticator-based Security

CVSS3: 5.3
EPSS: Низкий
fstec логотип

BDU:2021-03305

около 4 лет назад

Уязвимость программной платформы для разработки и управления веб-приложениями Symfony, связанная с раскрытием информации, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2021-21424

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. The ability to enumerate users was possible without relevant permissions due to different handling depending on whether the user existed or not when attempting to use the switch users functionality. We now ensure that 403s are returned whether the user exists or not if a user cannot switch to a user or if the user does not exist. The patch for this issue is available for branch 3.4.

CVSS3: 5.3
0%
Низкий
около 4 лет назад
nvd логотип
CVE-2021-21424

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. The ability to enumerate users was possible without relevant permissions due to different handling depending on whether the user existed or not when attempting to use the switch users functionality. We now ensure that 403s are returned whether the user exists or not if a user cannot switch to a user or if the user does not exist. The patch for this issue is available for branch 3.4.

CVSS3: 5.3
0%
Низкий
около 4 лет назад
debian логотип
CVE-2021-21424

Symfony is a PHP framework for web and console applications and a set ...

CVSS3: 5.3
0%
Низкий
около 4 лет назад
github логотип
GHSA-5pv8-ppvj-4h68

Prevent user enumeration using Guard or the new Authenticator-based Security

CVSS3: 5.3
0%
Низкий
около 4 лет назад
fstec логотип
BDU:2021-03305

Уязвимость программной платформы для разработки и управления веб-приложениями Symfony, связанная с раскрытием информации, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 5.3
0%
Низкий
около 4 лет назад

Уязвимостей на страницу