CVE-2024-50341

CVSS 3.1 Score 3.1 of 10 (low)

Details

Published Nov 6, 2024
Updated: Nov 8, 2024
CWE ID 287

Summary

CVE-2024-50341 is a vulnerability affecting the symfony/security-bundle module in Symphony PHP framework versions 6.4.10, 7.0.10, and 7.1.3. This module provides security integration into the Symfony full-stack framework. The issue arises when using the `Security::login` method for programmatic login, which bypasses the custom `user_checker` defined on the firewall. This can result in unwanted logins. To mitigate this risk, users are advised to upgrade to the latest versions, which now ensure the `user_checker` is called during programmatic logins. No known workarounds are available for this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share