Search CVE reports


Toggle filters

71 – 80 of 84 results


CVE-2018-11407

Medium priority

Some fixes available 1 of 2

An issue was discovered in the Ldap component in Symfony 2.8.x before 2.8.37, 3.3.x before 3.3.17, 3.4.x before 3.4.7, and 4.0.x before 4.0.7. It allows remote attackers to bypass authentication by logging in with a "null"...

1 affected package

symfony

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
symfony Not affected Not affected Fixed
Show less packages

CVE-2018-11406

Medium priority
Vulnerable

An issue was discovered in the Security component in Symfony 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x before 4.0.11. By default, a user's session is invalidated when the user is...

1 affected package

symfony

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
symfony Not affected Not affected Not affected Not affected Vulnerable
Show less packages

CVE-2018-11386

Medium priority

Some fixes available 1 of 2

An issue was discovered in the HttpFoundation component in Symfony 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x before 4.0.11. The PDOSessionHandler class allows storing sessions on...

1 affected package

symfony

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
symfony Fixed
Show less packages

CVE-2018-11385

Medium priority
Vulnerable

An issue was discovered in the Security component in Symfony 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x before 4.0.11. A session fixation vulnerability within the "Guard" login...

1 affected package

symfony

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
symfony Not affected Not affected Not affected Not affected Vulnerable
Show less packages

CVE-2017-16652

Medium priority
Ignored

An issue was discovered in Symfony 2.7.x before 2.7.38, 2.8.x before 2.8.31, 3.2.x before 3.2.14, and 3.3.x before 3.3.13. DefaultAuthenticationSuccessHandler or DefaultAuthenticationFailureHandler takes the content of the...

1 affected package

symfony

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
symfony Not affected Not affected Not affected Not affected Not affected
Show less packages

CVE-2016-2403

Medium priority
Ignored

Symfony before 2.8.6 and 3.x before 3.0.6 allows remote attackers to bypass authentication by logging in with an empty password and valid username, which triggers an unauthenticated bind.

1 affected package

symfony

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
symfony Not affected
Show less packages

CVE-2016-4423

Medium priority
Ignored

The attemptAuthentication function in Component/Security/Http/Firewall/UsernamePasswordFormAuthenticationListener.php in Symfony before 2.3.41, 2.7.x before 2.7.13, 2.8.x before 2.8.6, and 3.0.x before 3.0.6 does not limit the...

1 affected package

symfony

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
symfony Not affected Not affected Not affected Not affected Not affected
Show less packages

CVE-2016-1902

Medium priority
Ignored

The nextBytes function in the SecureRandom class in Symfony before 2.3.37, 2.6.x before 2.6.13, and 2.7.x before 2.7.9 does not properly generate random numbers when used with PHP 5.x without the paragonie/random_compat library...

1 affected package

symfony

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
symfony
Show less packages

CVE-2015-8125

Medium priority
Ignored

Symfony 2.3.x before 2.3.35, 2.6.x before 2.6.12, and 2.7.x before 2.7.7 might allow remote attackers to have unspecified impact via a timing attack involving the...

1 affected package

symfony

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
symfony Not affected
Show less packages

CVE-2015-8124

Medium priority
Ignored

Session fixation vulnerability in the "Remember Me" login feature in Symfony 2.3.x before 2.3.35, 2.6.x before 2.6.12, and 2.7.x before 2.7.7 allows remote attackers to hijack web sessions via a session id.

1 affected package

symfony

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
symfony Not affected
Show less packages