User enumeration In symfony
Description
User enumeration leak using switch user functionality in Symfony An issue was discovered in Symfony 4.2.0 to 4.2.11 and 4.3.0 to 4.3.7. The ability to enumerate users was possible due to different handling depending on whether the user existed when making unauthorized attempts to use the switch users functionality. This is related to symfony/security.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
debian 11 | 4.3.8+dfsg-1 | ||
debian 12 | 4.3.8+dfsg-1 | ||
debian 13 | 4.3.8+dfsg-1 | ||
packagist | 4.2.12, 4.3.8 | ||
packagist | 4.2.12, 4.3.8 | ||
debian 14 | 4.3.8+dfsg-1 |
Aliases
1. 2. 3. 4. 5. 6.
References
1. 2. 3. 4. 5. 6.