Improper authentication in Symfony - CVE-2024-51996
Published: November 15, 2024
Vulnerability details
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to an error during authentication when using the persisted remember-me cookie. The application does not check if the username persisted in the database matches the username attached with the cookie. A remote non-authenticated attacker can bypass authentication process and gain unauthorized access to the application.
Affected software
Debian Linux
Ubuntu
php-symfony (Ubuntu package)
symfony (Debian package)
How to mitigate CVE-2024-51996
php-symfony (Ubuntu package) - update to Ubuntu Pro
symfony (Debian package) - update to 5.4.23+dfsg-1+deb12u4