Improper control of interaction frequency in Symfony - CVE-2019-18886
Published: November 22, 2019
Symfony
Detailed vulnerability description
The vulnerability allows a remote attacker to gain access to sensitive information on the target system.
The vulnerability exists in the "Security/Http" component due to different handling depending on whether the user existed or not when attempting to use the switch users functionality. A remote attacker can enumerate users on the target system.