PT-2024-9246 · Symfony+1 · Symfony+1

Markuspoerschke

·

Published

2024-02-07

·

Updated

2024-12-03

·

CVE-2024-36611

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions: Symfony version 7.07
Description: A security issue was identified in the FormLoginAuthenticator component of Symfony, where it failed to adequately handle cases where the username or password field of a login request is empty. This flaw could lead to various security risks, including improper authentication logic handling or denial of service. However, the supplier has concluded that this report is false.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Incorrect Authorization

Improper Authentication

Weakness Enumeration

Related Identifiers

BDU:2024-10934
CVE-2024-36611
GHSA-7Q22-X757-CMGC

Affected Products

Debian
Symfony