cbcvebase.
CVE-2018-11385
published 2018-06-13

CVE-2018-11385: An issue was discovered in the Security component in Symfony 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x…

PriorityP342high8.1CVSS 3.0
AVNACHPRNUINSUCHIHAH
EPSS
2.01%
78.8th percentile
An issue was discovered in the Security component in Symfony 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x before 4.0.11. A session fixation vulnerability within the "Guard" login feature may allow an attacker to impersonate a victim towards the web application if the session id value was previously known to the attacker.

Affected

28 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debiansymfony< symfony 3.4.12+dfsg-1 (bookworm)symfony 3.4.12+dfsg-1 (bookworm)
fedoraprojectfedora
sensiolabssymfony>= 2.7.0 < 2.7.482.7.48
sensiolabssymfony>= 2.8.0 < 2.8.412.8.41
sensiolabssymfony>= 3.3.0 < 3.3.173.3.17
sensiolabssymfony>= 3.4.0 < 3.4.113.4.11
sensiolabssymfony>= 4.0.0 < 4.0.114.0.11
symfonysecurity>= 2.7.0 < 2.7.482.7.48
symfonysecurity>= 2.8.0 < 2.8.412.8.41
symfonysecurity>= 3.0.0 < 3.3.173.3.17
symfonysecurity>= 3.4.0 < 3.4.113.4.11
symfonysecurity>= 4.0.0 < 4.0.114.0.11
symfonysecurity-http>= 2.7.0 < 2.7.482.7.48
symfonysecurity-http>= 2.8.0 < 2.8.412.8.41
symfonysecurity-http>= 3.0.0 < 3.3.173.3.17
symfonysecurity-http>= 3.4.0 < 3.4.113.4.11
symfonysecurity-http>= 4.0.0 < 4.0.114.0.11
symfonysymfony>= 0 < 3.4.12+dfsg-13.4.12+dfsg-1
symfonysymfony>= 0 < 3.4.12+dfsg-13.4.12+dfsg-1
symfonysymfony>= 0 < 3.4.12+dfsg-13.4.12+dfsg-1
symfonysymfony>= 0 < 3.4.12+dfsg-13.4.12+dfsg-1
symfonysymfony>= 2.7.0 < 2.7.482.7.48
symfonysymfony>= 2.8.0 < 2.8.412.8.41

CVSS provenance

nvdv3.08.1HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.1HIGH
vendor_debian8.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.