CVE-2018-11406Cross-Site Request Forgery in Symfony

Severity
8.8HIGHNVD
EPSS
0.2%
top 59.79%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 13
Latest updateMay 14

Description

An issue was discovered in the Security component in Symfony 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x before 4.0.11. By default, a user's session is invalidated when the user is logged out. This behavior can be disabled through the invalidate_session option. In this case, CSRF tokens were not erased during logout which allowed for CSRF token fixation.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages6 packages

Packagistsymfony/security2.7.02.7.48+4
Packagistsymfony/security-http2.7.02.7.48+4
Packagistsymfony/security-bundle2.7.02.7.48+4
Packagistsymfony/symfony2.7.02.7.48+4
NVDsensiolabs/symfony2.7.02.7.48+4

Also affects: Debian Linux 9.0

🔴Vulnerability Details

4
GHSA
Symfony CSRF Token Fixation2022-05-14
OSV
Symfony CSRF Token Fixation2022-05-14
CVEList
CVE-2018-11406: An issue was discovered in the Security component in Symfony 22018-06-13
OSV
CVE-2018-11406: An issue was discovered in the Security component in Symfony 22018-06-13

📋Vendor Advisories

1
Debian
CVE-2018-11406: symfony - An issue was discovered in the Security component in Symfony 2.7.x before 2.7.48...2018

💬Community

6
Bugzilla
CVE-2017-16652 CVE-2018-11385 CVE-2018-11386 CVE-2018-11406 CVE-2018-11407 CVE-2018-11408 php-symfony4: php-symfony: Multiple flaws [fedora-all]2018-06-15
Bugzilla
CVE-2017-16652 CVE-2018-11385 CVE-2018-11386 CVE-2018-11406 CVE-2018-11407 CVE-2018-11408 php-symfony-symfony: php-symfony: Multiple flaws [epel-6]2018-06-15
Bugzilla
CVE-2017-16652 CVE-2018-11385 CVE-2018-11386 CVE-2018-11406 CVE-2018-11407 CVE-2018-11408 php-symfony3: php-symfony: Multiple flaws [fedora-all]2018-06-15
Bugzilla
CVE-2017-16652 CVE-2018-11385 CVE-2018-11386 CVE-2018-11406 CVE-2018-11407 CVE-2018-11408 php-symfony: Multiple flaws2018-06-14
Bugzilla
CVE-2017-16652 CVE-2018-11385 CVE-2018-11386 CVE-2018-11406 CVE-2018-11407 CVE-2018-11408 php-symfony: Multiple flaws [fedora-all]2018-06-14
CVE-2018-11406 — Cross-Site Request Forgery in Symfony | cvebase