PT-2024-9246 · Symfony+1 · Symfony+1
Markuspoerschke
·
Published
2024-02-07
·
Updated
2024-12-03
·
CVE-2024-36611
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions:
Symfony version 7.07
Description:
A security issue was identified in the FormLoginAuthenticator component of Symfony, where it failed to adequately handle cases where the
username or password field of a login request is empty. This flaw could lead to various security risks, including improper authentication logic handling or denial of service. However, the supplier has concluded that this report is false.Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
DoS
Incorrect Authorization
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Debian
Symfony