Symfony · Symfony/Securitybundle · CVE-2024-50341
Name of the Vulnerable Software and Affected Versions:
symfony/security-bundle versions prior to 6.4.10
symfony/security-bundle versions prior to 7.0.10
symfony/security-bundle versions prior to 7.1.3
Description:
The custom `user checker` defined on a firewall is not called when logging in programmatically with the `Security::login` method, leading to unwanted login.
Recommendations:
For versions prior to 6.4.10, upgrade to version 6.4.10 or later.
For versions prior to 7.0.10, upgrade to version 7.0.10 or later.
For versions prior to 7.1.3, upgrade to version 7.1.3 or later.