CVE-2024-36611
CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th
In Symfony v7.07, a security vulnerability was identified in the FormLoginAuthenticator component, where it failed to adequately handle cases where the username or password field of a login request is empty. This flaw could lead to various security risks, including improper authentication logic handling or denial of service. NOTE: the Supplier has concluded that this is a false report.
| Vendor | n/a |
| Product | n/a |
| Published | Nov 29, 2024 |
| Last Updated | Jan 6, 2025 |
Stay Ahead of the Next One
Get instant alerts for n/a n/a
Be the first to know when new high vulnerabilities affecting n/a n/a are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
n/a / n/a
n/a
References
github.com: https://github.com/symfony/symfony/commit/a804ca15fcad279d7727b91d12a667fd5b925995 github.com: https://github.com/symfony/symfony/blob/v7.0.7/src/Symfony/Component/Security/Http/Authenticator/FormLoginAuthenticator.php#L132 gist.github.com: https://gist.github.com/1047524396/3581425e0911b716cf8ce4fa30e41e6c github.com: https://github.com/github/advisory-database/pull/5046 github.com: https://github.com/symfony/symfony/issues/59077#issuecomment-2513935018