CVE-2015-8124
published 2015-12-07CVE-2015-8124: Session fixation vulnerability in the "Remember Me" login feature in Symfony 2.3.x before 2.3.35, 2.6.x before 2.6.12, and 2.7.x before 2.7.7 allows remote…
PriorityP430medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
2.71%
84.3th percentile
Session fixation vulnerability in the "Remember Me" login feature in Symfony 2.3.x before 2.3.35, 2.6.x before 2.6.12, and 2.7.x before 2.7.7 allows remote attackers to hijack web sessions via a session id.
Affected
67 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | symfony | < symfony 2.7.7+dfsg-1 (bookworm) | symfony 2.7.7+dfsg-1 (bookworm) |
| sensiolabs | symfony | — | — |
| sensiolabs | symfony | — | — |
| sensiolabs | symfony | — | — |
| sensiolabs | symfony | — | — |
| sensiolabs | symfony | — | — |
| sensiolabs | symfony | — | — |
| sensiolabs | symfony | — | — |
| sensiolabs | symfony | — | — |
| sensiolabs | symfony | — | — |
| sensiolabs | symfony | — | — |
| sensiolabs | symfony | — | — |
| sensiolabs | symfony | — | — |
| sensiolabs | symfony | — | — |
| sensiolabs | symfony | — | — |
| sensiolabs | symfony | — | — |
| sensiolabs | symfony | — | — |
| sensiolabs | symfony | — | — |
| sensiolabs | symfony | — | — |
| sensiolabs | symfony | — | — |
| sensiolabs | symfony | — | — |
| sensiolabs | symfony | — | — |
| sensiolabs | symfony | — | — |
| sensiolabs | symfony | — | — |
| sensiolabs | symfony | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_debian6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2015-8124: symfony - Session fixation vulnerability in the "Remember Me" login feature in Symfony 2.3...
vendor_debian·2015·CVSS 6.8
CVE-2015-8124 [MEDIUM] CVE-2015-8124: symfony - Session fixation vulnerability in the "Remember Me" login feature in Symfony 2.3...
Session fixation vulnerability in the "Remember Me" login feature in Symfony 2.3.x before 2.3.35, 2.6.x before 2.6.12, and 2.7.x before 2.7.7 allows remote attackers to hijack web sessions via a session id.
Scope: local
bookworm: resolved (fixed in 2.7.7+dfsg-1)
bullseye: resolved (fixed in 2.7.7+dfsg-1)
forky: resolved (fixed in 2.7.7+dfsg-1)
sid: resolved (fixed in 2.7.7+dfsg-1)
trixie: resolved (fixed in 2.7.7+dfsg-1)
OSV
Symfony Session Fixation Vulnerability
osv·2022-05-14
CVE-2015-8124 [LOW] Symfony Session Fixation Vulnerability
Symfony Session Fixation Vulnerability
A session fixation vulnerability within the "Remember Me" login feature allows an attacker to impersonate the victim towards the web application if the session id value was previously known to the attacker. This issue has been fixed in Symfony 2.3.35, 2.6.12, and 2.7.7. Note that no fixes are provided for Symfony 2.4 and 2.5 as they are not maintained anymore. Symfony 2.8 and 3.0 haven't been released yet and the fix will be included in their first stable releases.
GHSA
Symfony Session Fixation Vulnerability
ghsa·2022-05-14
CVE-2015-8124 [LOW] CWE-384 Symfony Session Fixation Vulnerability
Symfony Session Fixation Vulnerability
A session fixation vulnerability within the "Remember Me" login feature allows an attacker to impersonate the victim towards the web application if the session id value was previously known to the attacker. This issue has been fixed in Symfony 2.3.35, 2.6.12, and 2.7.7. Note that no fixes are provided for Symfony 2.4 and 2.5 as they are not maintained anymore. Symfony 2.8 and 3.0 haven't been released yet and the fix will be included in their first stable releases.
OSV
CVE-2015-8124: Session fixation vulnerability in the "Remember Me" login feature in Symfony 2
osv·2015-12-07·CVSS 6.8
CVE-2015-8124 [MEDIUM] CVE-2015-8124: Session fixation vulnerability in the "Remember Me" login feature in Symfony 2
Session fixation vulnerability in the "Remember Me" login feature in Symfony 2.3.x before 2.3.35, 2.6.x before 2.6.12, and 2.7.x before 2.7.7 allows remote attackers to hijack web sessions via a session id.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-8124 CVE-2015-8125 php-symfony: Session fixation and remote timing attack vulnerabilities [fedora-all]
bugzilla·2015-11-25·CVSS 6.8
CVE-2015-8124 [MEDIUM] CVE-2015-8124 CVE-2015-8125 php-symfony: Session fixation and remote timing attack vulnerabilities [fedora-all]
CVE-2015-8124 CVE-2015-8125 php-symfony: Session fixation and remote timing attack vulnerabilities [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affec
Bugzilla
CVE-2015-8124 CVE-2015-8125 php-symfony: Session fixation and remote timing attack vulnerabilities
bugzilla·2015-11-25·CVSS 6.8
CVE-2015-8124 [MEDIUM] CVE-2015-8124 CVE-2015-8125 php-symfony: Session fixation and remote timing attack vulnerabilities
CVE-2015-8124 CVE-2015-8125 php-symfony: Session fixation and remote timing attack vulnerabilities
Two security issues in php-symfony were found:
CVE-2015-8124: Session Fixation in the "Remember Me" Login Feature
A session fixation vulnerability within the "Remember Me" login feature allows an attacker to impersonate the victim towards the web application if the session id value was previously known to the attacker.
Upstream patch:
https://github.com/fabpot/symfony/commit/f88e600833b6822db5873e25deaefd14948e4878
CVE-2015-8125: Potential Remote Timing Attack Vulnerability in Security Remember-Me Service
Several potential remote timing attack vulnerabilities were discovered in classes from the Symfony Security component (Symfony\Component\Security\Http\RememberMe\PersistentTokenBasedR
Bugzilla
CVE-2015-8124 CVE-2015-8125 php-symfony: Session fixation and remote timing attack vulnerabilities [epel-all]
bugzilla·2015-11-25·CVSS 6.8
CVE-2015-8124 [MEDIUM] CVE-2015-8124 CVE-2015-8125 php-symfony: Session fixation and remote timing attack vulnerabilities [epel-all]
CVE-2015-8124 CVE-2015-8125 php-symfony: Session fixation and remote timing attack vulnerabilities [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue af
http://lists.fedoraproject.org/pipermail/package-announce/2015-December/173271.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-December/173300.htmlhttp://seclists.org/fulldisclosure/2015/Dec/89http://www.debian.org/security/2015/dsa-3402http://www.securityfocus.com/archive/1/537183/100/0/threadedhttp://www.securityfocus.com/bid/77694https://symfony.com/blog/cve-2015-8124-session-fixation-in-the-remember-me-login-featurehttp://lists.fedoraproject.org/pipermail/package-announce/2015-December/173271.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-December/173300.htmlhttp://seclists.org/fulldisclosure/2015/Dec/89http://www.debian.org/security/2015/dsa-3402http://www.securityfocus.com/archive/1/537183/100/0/threadedhttp://www.securityfocus.com/bid/77694https://symfony.com/blog/cve-2015-8124-session-fixation-in-the-remember-me-login-feature
2015-12-07
Published