6.5
CVE-2026-50157
- EPSS 0.5%
- Veröffentlicht 14.09.2026 17:06:23
- Zuletzt bearbeitet 30.09.2026 17:43:24
- Erkennungen
Auth0 Symfony: Bearer Token Accepted via URL Query Parameter in Auth0 Symfony SDK
Auth0 Symfony is a Symfony SDK for Auth0 Authentication and Management APIs. From 5.0.0-BETA0 until 5.9.0, the Authorizer::authenticate() and Authorizer::supports() paths in the Authorizer security authenticator may accept OAuth 2.0 bearer access tokens from the token URL query parameter as well as the Authorization header for protected HTTP routes. Query-string tokens can be recorded in server logs, browser history, or referrer data and then replayed against protected API endpoints. This issue is fixed in version 5.9.0.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Herstellerauth0
≫
Produkt
symfony
Version
>= 5.0.0-BETA0, < 5.9.0
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.5% | 0.413 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security-advisories@github.com | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
CWE-598 Use of HTTP Request With Sensitive Query String
The web application uses an HTTP method to process a request, but the request includes sensitive information in the query string.
https://github.com/auth0/symfony/security/advisories/GHSA-ffq7-hh2j-r24p
https://github.com/auth0/symfony/commit/bd1851b14ae15e99cbe87c96496cf25da025288a
https://github.com/auth0/symfony/releases/tag/5.9.0