PT-2024-9246 · Symfony+1 · Symfony+1

·

CVE-2024-36611

·

Published

2024-02-07

·

Updated

2024-12-03

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions: Symfony version 7.07
Description: A security issue was identified in the FormLoginAuthenticator component of Symfony, where it failed to adequately handle cases where the username or password field of a login request is empty. This flaw could lead to various security risks, including improper authentication logic handling or denial of service. However, the supplier has concluded that this report is false.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Improper Authentication

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-10934
CVE-2024-36611
GHSA-7Q22-X757-CMGC

Affected Products

Debian
Symfony