๐Ÿ” CVE Alert

CVE-2024-36611

HIGH 7.5
CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th

In Symfony v7.07, a security vulnerability was identified in the FormLoginAuthenticator component, where it failed to adequately handle cases where the username or password field of a login request is empty. This flaw could lead to various security risks, including improper authentication logic handling or denial of service. NOTE: the Supplier has concluded that this is a false report.

Vendor n/a
Product n/a
Published Nov 29, 2024
Last Updated Jan 6, 2025
Stay Ahead of the Next One

Get instant alerts for n/a n/a

Be the first to know when new high vulnerabilities affecting n/a n/a are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

n/a / n/a
n/a

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/symfony/symfony/commit/a804ca15fcad279d7727b91d12a667fd5b925995 github.com: https://github.com/symfony/symfony/blob/v7.0.7/src/Symfony/Component/Security/Http/Authenticator/FormLoginAuthenticator.php#L132 gist.github.com: https://gist.github.com/1047524396/3581425e0911b716cf8ce4fa30e41e6c github.com: https://github.com/github/advisory-database/pull/5046 github.com: https://github.com/symfony/symfony/issues/59077#issuecomment-2513935018