CVE-2018-11408
- EPSS 0.31%
- Published 13.06.2018 16:29:01
- Last modified 21.11.2024 03:43:18
The security handlers in the Security component in Symfony in 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x before 4.0.11 have an Open redirect vulnerability when security.http_utils is inlined by a con...
CVE-2018-11407
- EPSS 0.2%
- Published 13.06.2018 16:29:01
- Last modified 21.11.2024 03:43:18
An issue was discovered in the Ldap component in Symfony 2.8.x before 2.8.37, 3.3.x before 3.3.17, 3.4.x before 3.4.7, and 4.0.x before 4.0.7. It allows remote attackers to bypass authentication by logging in with a "null" password and valid username...
CVE-2018-11385
- EPSS 0.95%
- Published 13.06.2018 16:29:00
- Last modified 21.11.2024 03:43:16
An issue was discovered in the Security component in Symfony 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x before 4.0.11. A session fixation vulnerability within the "Guard" login feature may allow an a...
CVE-2017-16652
- EPSS 0.22%
- Published 13.06.2018 16:29:00
- Last modified 21.11.2024 03:16:46
An issue was discovered in Symfony 2.7.x before 2.7.38, 2.8.x before 2.8.31, 3.2.x before 3.2.14, and 3.3.x before 3.3.13. DefaultAuthenticationSuccessHandler or DefaultAuthenticationFailureHandler takes the content of the _target_path parameter and ...
CVE-2018-11386
- EPSS 1.09%
- Published 13.06.2018 16:29:00
- Last modified 21.11.2024 03:43:16
An issue was discovered in the HttpFoundation component in Symfony 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x before 4.0.11. The PDOSessionHandler class allows storing sessions on a PDO connection. U...
CVE-2018-11406
- EPSS 0.19%
- Published 13.06.2018 16:29:00
- Last modified 21.11.2024 03:43:17
An issue was discovered in the Security component in Symfony 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x before 4.0.11. By default, a user's session is invalidated when the user is logged out. This be...
CVE-2016-2403
- EPSS 0.15%
- Published 07.02.2017 17:59:00
- Last modified 20.04.2025 01:37:25
Symfony before 2.8.6 and 3.x before 3.0.6 allows remote attackers to bypass authentication by logging in with an empty password and valid username, which triggers an unauthenticated bind.
CVE-2016-4423
- EPSS 1.44%
- Published 01.06.2016 22:59:02
- Last modified 12.04.2025 10:46:40
The attemptAuthentication function in Component/Security/Http/Firewall/UsernamePasswordFormAuthenticationListener.php in Symfony before 2.3.41, 2.7.x before 2.7.13, 2.8.x before 2.8.6, and 3.0.x before 3.0.6 does not limit the length of a username st...
CVE-2016-1902
- EPSS 0.4%
- Published 01.06.2016 22:59:01
- Last modified 12.04.2025 10:46:40
The nextBytes function in the SecureRandom class in Symfony before 2.3.37, 2.6.x before 2.6.13, and 2.7.x before 2.7.9 does not properly generate random numbers when used with PHP 5.x without the paragonie/random_compat library and the openssl_random...
CVE-2015-8125
- EPSS 1.01%
- Published 07.12.2015 20:59:15
- Last modified 12.04.2025 10:46:40
Symfony 2.3.x before 2.3.35, 2.6.x before 2.6.12, and 2.7.x before 2.7.7 might allow remote attackers to have unspecified impact via a timing attack involving the (1) Symfony/Component/Security/Http/RememberMe/PersistentTokenBasedRememberMeServices o...