Symfony before 2.8.6 and 3.x before 3.0.6 allows remote attackers to bypass authentication by logging in with an empty password and valid username, which triggers an unauthenticated bind.
Metrics
Affected Vendors & Products
Advisories
Source | ID | Title |
---|---|---|
![]() |
DSA-4262-1 | symfony security update |
![]() |
EUVD-2022-5646 | Symfony before 2.8.6 and 3.x before 3.0.6 allows remote attackers to bypass authentication by logging in with an empty password and valid username, which triggers an unauthenticated bind. |
![]() |
GHSA-wvj5-r78r-hhfq | Symfony Authentication Bypass |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T23:24:49.284Z
Reserved: 2016-02-18T00:00:00
Link: CVE-2016-2403

No data.

Status : Deferred
Published: 2017-02-07T17:59:00.303
Modified: 2025-04-20T01:37:25.860
Link: CVE-2016-2403

No data.

No data.