PT-2023-7208 · Symfony · Symfony

Robertme

·

Publicado

2023-11-10

·

Atualizado

2024-03-06

·

CVE-2023-46733

CVSS v2.0

6.8

Média

VetorAV:N/AC:L/Au:S/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions Symfony versions 5.4.21 through 5.4.30 Symfony versions 6.2.7 through 6.3.7
Description The issue is related to the incorrect management of sessions by the SessionStrategyListener function in the Symfony platform. This can allow a remote attacker to compromise the integrity of protected information. The problem arises when the user identifier does not change between the verification phase and successful login, but the token type changes from partially-authenticated to fully-authenticated. In such cases, the session ID should be regenerated to prevent possible session fixations, but this does not occur.
Recommendations For Symfony versions 5.4.21 through 5.4.30, update to version 5.4.31 or later. For Symfony versions 6.2.7 through 6.3.7, update to version 6.3.8 or later. As a temporary workaround, consider regenerating the session ID after every successful login to prevent possible session fixations.

Exploit

Correção

Session Fixation

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-08236
BIT-SYMFONY-2023-46733
CVE-2023-46733
GHSA-M2WJ-R6G3-FXFX

Produtos afetados

Symfony