CVE-2023-46733
published 2023-11-10CVE-2023-46733: Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Starting in versions 5.4.21 and 6.2.7 and prior to versions…
PriorityP335medium6.5CVSS 3.1
AVNACLPRLUINSUCNIHAN
EPSS
0.69%
48.9th percentile
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Starting in versions 5.4.21 and 6.2.7 and prior to versions 5.4.31 and 6.3.8, `SessionStrategyListener` does not migrate the session after every successful login. It does so only in case the logged in user changes by means of checking the user identifier. In some use cases, the user identifier doesn't change between the verification phase and the successful login, while the token itself changes from one type (partially-authenticated) to another (fully-authenticated). When this happens, the session id should be regenerated to prevent possible session fixations, which is not the case at the moment. As of versions 5.4.31 and 6.3.8, Symfony now checks the type of the token in addition to the user identifier before deciding whether the session id should be regenerated.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | symfony | < symfony 5.4.23+dfsg-1+deb12u1 (bookworm) | symfony 5.4.23+dfsg-1+deb12u1 (bookworm) |
| sensiolabs | symfony | >= 5.4.21 < 5.4.31 | 5.4.31 |
| sensiolabs | symfony | >= 6.2.7 < 6.3.8 | 6.3.8 |
| symfony | security-http | >= 5.4.21 < 5.4.31 | 5.4.31 |
| symfony | security-http | >= 6.2.7 < 6.3.8 | 6.3.8 |
| symfony | symfony | — | — |
| symfony | symfony | — | — |
| symfony | symfony | >= 0 < 5.4.23+dfsg-1+deb12u1 | 5.4.23+dfsg-1+deb12u1 |
| symfony | symfony | >= 0 < 5.4.31+dfsg-1 | 5.4.31+dfsg-1 |
| symfony | symfony | >= 0 < 5.4.31+dfsg-1 | 5.4.31+dfsg-1 |
| symfony | symfony | >= 5.4.21 < 5.4.31 | 5.4.31 |
| symfony | symfony | >= 6.2.7 < 6.3.8 | 6.3.8 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
osv6.5MEDIUM
vendor_debian6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Symfony possible session fixation vulnerability
osv·2023-11-12
CVE-2023-46733 [MEDIUM] Symfony possible session fixation vulnerability
Symfony possible session fixation vulnerability
### Description
SessionStrategyListener does not always migrate the session after a successful login. It only migrate the session when the logged-in user identifier changes. In some use cases, the user identifier doesn't change between the verification phase and the successful login, while the token itself changes from one type (partially-authenticated) to another (fully-authenticated). When this happens, the session id should be regenerated to prevent possible session fixations.
### Resolution
Symfony now checks the type of the token in addition to the user identifier before deciding whether the session id should be regenerated.
The patch for this issue is available [here](https://github.com/symfony/symfony/commit/dc356499d5ceb86f7cf2b4
GHSA
Symfony possible session fixation vulnerability
ghsa·2023-11-12
CVE-2023-46733 [MEDIUM] CWE-384 Symfony possible session fixation vulnerability
Symfony possible session fixation vulnerability
### Description
SessionStrategyListener does not always migrate the session after a successful login. It only migrate the session when the logged-in user identifier changes. In some use cases, the user identifier doesn't change between the verification phase and the successful login, while the token itself changes from one type (partially-authenticated) to another (fully-authenticated). When this happens, the session id should be regenerated to prevent possible session fixations.
### Resolution
Symfony now checks the type of the token in addition to the user identifier before deciding whether the session id should be regenerated.
The patch for this issue is available [here](https://github.com/symfony/symfony/commit/dc356499d5ceb86f7cf2b4
OSV
CVE-2023-46733: Symfony is a PHP framework for web and console applications and a set of reusable PHP components
osv·2023-11-10·CVSS 6.5
CVE-2023-46733 [MEDIUM] CVE-2023-46733: Symfony is a PHP framework for web and console applications and a set of reusable PHP components
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Starting in versions 5.4.21 and 6.2.7 and prior to versions 5.4.31 and 6.3.8, `SessionStrategyListener` does not migrate the session after every successful login. It does so only in case the logged in user changes by means of checking the user identifier. In some use cases, the user identifier doesn't change between the verification phase and the successful login, while the token itself changes from one type (partially-authenticated) to another (fully-authenticated). When this happens, the session id should be regenerated to prevent possible session fixations, which is not the case at the moment. As of versions 5.4.31 and 6.3.8, Symfony now checks the type of the token in addition to the user
Debian
CVE-2023-46733: symfony - Symfony is a PHP framework for web and console applications and a set of reusabl...
vendor_debian·2023·CVSS 6.5
CVE-2023-46733 [MEDIUM] CVE-2023-46733: symfony - Symfony is a PHP framework for web and console applications and a set of reusabl...
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Starting in versions 5.4.21 and 6.2.7 and prior to versions 5.4.31 and 6.3.8, `SessionStrategyListener` does not migrate the session after every successful login. It does so only in case the logged in user changes by means of checking the user identifier. In some use cases, the user identifier doesn't change between the verification phase and the successful login, while the token itself changes from one type (partially-authenticated) to another (fully-authenticated). When this happens, the session id should be regenerated to prevent possible session fixations, which is not the case at the moment. As of versions 5.4.31 and 6.3.8, Symfony now checks the type of the token in addition to the user
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/symfony/symfony/commit/7467bd7e3f888b333102bc664b5e02ef1e7f88b9https://github.com/symfony/symfony/commit/dc356499d5ceb86f7cf2b4c7f032eca97061ed74https://github.com/symfony/symfony/security/advisories/GHSA-m2wj-r6g3-fxfxhttps://github.com/symfony/symfony/commit/7467bd7e3f888b333102bc664b5e02ef1e7f88b9https://github.com/symfony/symfony/commit/dc356499d5ceb86f7cf2b4c7f032eca97061ed74https://github.com/symfony/symfony/security/advisories/GHSA-m2wj-r6g3-fxfx
2023-11-10
Published