In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, a vulnerability would allow an attacker to authenticate as a privileged user on sites with user registration and remember me login functionality enabled. This is related to symfony/security.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-1778-1 | symfony security update |
Debian DSA |
DSA-4441-1 | symfony security update |
EUVD |
EUVD-2020-0300 | In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, a vulnerability would allow an attacker to authenticate as a privileged user on sites with user registration and remember me login functionality enabled. This is related to symfony/security. |
Github GHSA |
GHSA-cchx-mfrc-fwqr | Improper authentication in Symfony |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T22:40:15.264Z
Reserved: 2019-04-07T00:00:00
Link: CVE-2019-10911
No data.
Status : Modified
Published: 2019-05-16T22:29:00.500
Modified: 2024-11-21T04:20:07.927
Link: CVE-2019-10911
No data.
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
EUVD
Github GHSA