7.5

CVE-2016-4423

The attemptAuthentication function in Component/Security/Http/Firewall/UsernamePasswordFormAuthenticationListener.php in Symfony before 2.3.41, 2.7.x before 2.7.13, 2.8.x before 2.8.6, and 3.0.x before 3.0.6 does not limit the length of a username stored in a session, which allows remote attackers to cause a denial of service (session storage consumption) via a series of authentication attempts with long, non-existent usernames.

Data is provided by the National Vulnerability Database (NVD)
SensiolabsSymfony Version <= 2.3.40
SensiolabsSymfony Version2.7.0
SensiolabsSymfony Version2.7.1
SensiolabsSymfony Version2.7.2
SensiolabsSymfony Version2.7.3
SensiolabsSymfony Version2.7.4
SensiolabsSymfony Version2.7.5
SensiolabsSymfony Version2.7.6
SensiolabsSymfony Version2.7.7
SensiolabsSymfony Version2.7.8
SensiolabsSymfony Version2.7.9
SensiolabsSymfony Version2.7.10
SensiolabsSymfony Version2.7.11
SensiolabsSymfony Version2.7.12
SensiolabsSymfony Version2.8.0
SensiolabsSymfony Version2.8.1
SensiolabsSymfony Version2.8.2
SensiolabsSymfony Version2.8.3
SensiolabsSymfony Version2.8.4
SensiolabsSymfony Version2.8.5
SensiolabsSymfony Version3.0.0
SensiolabsSymfony Version3.0.1
SensiolabsSymfony Version3.0.2
SensiolabsSymfony Version3.0.3
SensiolabsSymfony Version3.0.4
SensiolabsSymfony Version3.0.5
DebianDebian Linux Version8.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 1.44% 0.789
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P