Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-5813-1 | symfony security update |
EUVD |
EUVD-2024-3234 | Symphony process is a module for the Symphony PHP framework which executes commands in sub-processes. When consuming a persisted remember-me cookie, Symfony does not check if the username persisted in the database matches the username attached with the cookie, leading to authentication bypass. This vulnerability is fixed in 5.4.47, 6.4.15, and 7.1.8. |
Github GHSA |
GHSA-cg23-qf8f-62rr | Symfony has an Authentication Bypass via RememberMe |
Ubuntu USN |
USN-7272-1 | Symfony vulnerabilities |
Wed, 13 Nov 2024 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Symphony Php Framework
Symphony Php Framework symphony Process |
|
| CPEs | cpe:2.3:a:symphony_php_framework:symphony_process:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Symphony Php Framework
Symphony Php Framework symphony Process |
|
| Metrics |
ssvc
|
Wed, 13 Nov 2024 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Symphony process is a module for the Symphony PHP framework which executes commands in sub-processes. When consuming a persisted remember-me cookie, Symfony does not check if the username persisted in the database matches the username attached with the cookie, leading to authentication bypass. This vulnerability is fixed in 5.4.47, 6.4.15, and 7.1.8. | |
| Title | Symphony has an Authentication Bypass via RememberMe | |
| Weaknesses | CWE-287 CWE-289 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-11-13T18:49:31.776Z
Reserved: 2024-11-04T17:46:16.776Z
Link: CVE-2024-51996
Updated: 2024-11-13T18:48:56.818Z
Status : Deferred
Published: 2024-11-13T17:15:11.870
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-51996
No data.
OpenCVE Enrichment
No data.
Debian DSA
EUVD
Github GHSA
Ubuntu USN