CVE-2024-50341

LOW

Symfony Security-bundle < 6.4.10 - Authentication Bypass

Title source: rule
STIX 2.1

Description

symfony/security-bundle is a module for the Symphony PHP framework which provides a tight integration of the Security component into the Symfony full-stack framework. The custom `user_checker` defined on a firewall is not called when Login Programmaticaly with the `Security::login` method, leading to unwanted login. As of versions 6.4.10, 7.0.10 and 7.1.3 the `Security::login` method now ensure to call the configured `user_checker`. All users are advised to upgrade. There are no known workarounds for this vulnerability.

Scores

CVSS v3 3.1
EPSS 0.0014
EPSS Percentile 34.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-287
Status published
Products (5)
symfony/security-bundle 6.2.0 - 6.4.10Packagist
symfony/symfony 6.2.0 - 6.4.10Packagist
symfony/symfony >= 6.2.0, < 6.4.10
symfony/symfony >= 7.0.0, < 7.0.10
symfony/symfony >= 7.1.0, < 7.1.3
Published Nov 06, 2024
Tracked Since Feb 18, 2026