cbcvebase.
CVE-2024-50341
published 2024-11-06

CVE-2024-50341: symfony/security-bundle is a module for the Symphony PHP framework which provides a tight integration of the Security component into the Symfony full-stack…

PriorityP413low3.1CVSS 3.1
AVNACHPRLUINSUCNILAN
EPSS
0.32%
24.1th percentile
symfony/security-bundle is a module for the Symphony PHP framework which provides a tight integration of the Security component into the Symfony full-stack framework. The custom `user_checker` defined on a firewall is not called when Login Programmaticaly with the `Security::login` method, leading to unwanted login. As of versions 6.4.10, 7.0.10 and 7.1.3 the `Security::login` method now ensure to call the configured `user_checker`. All users are advised to upgrade. There are no known workarounds for this vulnerability.

Affected

15 ranges
VendorProductVersion rangeFixed in
debiansymfony< symfony 6.4.10+dfsg-1 (forky)symfony 6.4.10+dfsg-1 (forky)
symfonysecurity-bundle>= 6.2.0 < 6.4.106.4.10
symfonysecurity-bundle>= 7.0.0 < 7.0.107.0.10
symfonysecurity-bundle>= 7.1.0 < 7.1.37.1.3
symfonysymfony
symfonysymfony
symfonysymfony
symfonysymfony>= 0 < 6.4.10+dfsg-16.4.10+dfsg-1
symfonysymfony>= 0 < 6.4.10+dfsg-16.4.10+dfsg-1
symfonysymfony>= 0 < 4.3.8+dfsg-1ubuntu1+esm24.3.8+dfsg-1ubuntu1+esm2
symfonysymfony>= 0 < 5.4.4+dfsg-1ubuntu8+esm15.4.4+dfsg-1ubuntu8+esm1
symfonysymfony>= 0 < 6.4.5+dfsg-3ubuntu3+esm16.4.5+dfsg-3ubuntu3+esm1
symfonysymfony>= 6.2.0 < 6.4.106.4.10
symfonysymfony>= 7.0.0 < 7.0.107.0.10
symfonysymfony>= 7.1.0 < 7.1.37.1.3

CVSS provenance

nvdv3.13.1LOWCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
osv8.8HIGH
vendor_ubuntu5.9MEDIUM
vendor_debian3.1LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.