PT-2021-24419 · Symfony · Symfony
Published
2021-05-17
·
Updated
2021-05-17
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions:
symfony versions prior to 3.4
Description:
The issue allowed user enumeration without proper permissions due to distinct exception messages for existing and non-existing users. Additionally, a timing attack could be used by comparing the time taken to authenticate existing and non-existing users.
Recommendations:
For symfony versions prior to 3.4, update to version 3.4 or later to resolve the issue. As a temporary workaround, consider modifying the authentication mechanism to return uniform error messages for invalid passwords and non-existent users, regardless of the user's existence.
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Symfony