Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-7q22-x757-cmgc | Withdrawn Advisory: Symfony http-security has authentication bypass |
Tue, 03 Dec 2024 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Symfony v7.07, a security vulnerability was identified in the FormLoginAuthenticator component, where it failed to adequately handle cases where the username or password field of a login request is empty. This flaw could lead to various security risks, including improper authentication logic handling or denial of service. | In Symfony v7.07, a security vulnerability was identified in the FormLoginAuthenticator component, where it failed to adequately handle cases where the username or password field of a login request is empty. This flaw could lead to various security risks, including improper authentication logic handling or denial of service. NOTE: the Supplier has concluded that this is a false report. |
| References |
|
Tue, 03 Dec 2024 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Symfony
Symfony symfony |
|
| Weaknesses | CWE-863 | |
| CPEs | cpe:2.3:a:symfony:symfony:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Symfony
Symfony symfony |
|
| Metrics |
cvssV3_1
|
Fri, 29 Nov 2024 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Symfony v7.07, a security vulnerability was identified in the FormLoginAuthenticator component, where it failed to adequately handle cases where the username or password field of a login request is empty. This flaw could lead to various security risks, including improper authentication logic handling or denial of service. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-01-06T17:44:44.438Z
Reserved: 2024-05-30T00:00:00.000Z
Link: CVE-2024-36611
Updated: 2024-12-03T15:20:47.020Z
Status : Deferred
Published: 2024-11-29T19:15:06.780
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-36611
No data.
OpenCVE Enrichment
No data.
Github GHSA