symfony/security-http Security Advisories (15)
- 
                        [HIGH] CVE-2024-51996: Authentication Bypass via persisted RememberMe cookiePKSA-rqvm-b18n-vg69 CVE-2024-51996 GHSA-cg23-qf8f-62rr Affected version: >=5.3.0,<5.4.0|>=5.4.0,<5.4.47|>=6.0.0,<6.1.0|>=6.1.0,<6.2.0|>=6.2.0,<6.3.0|>=6.3.0,<6.4.0|>=6.4.0,<6.4.15|>=7.0.0,<7.1.0|>=7.1.0,<7.1.8 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [MEDIUM] CVE-2023-46733: Possible session fixationPKSA-5x8m-77gx-t86z CVE-2023-46733 GHSA-m2wj-r6g3-fxfx Affected version: >=5.4.0,<5.4.31|>=6.0.0,<6.1.0|>=6.1.0,<6.2.0|>=6.2.0,<6.3.0|>=6.3.0,<6.3.8 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [MEDIUM] CVE-2021-32693: Authentication granted to all firewalls instead of just onePKSA-gg1d-f43j-pd8z CVE-2021-32693 GHSA-rfcf-m67m-jcrq Affected version: >=5.3.0,<5.3.2 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [LOW] User enumeration in authentication mechanismsPKSA-41vr-83ph-45yn GHSA-g2qj-pmxm-9f8f Affected version: >=5.1.0,<5.2.8 Reported by: 
 GitHub
- 
                        [MEDIUM] CVE-2021-21424: Prevent user enumeration via response content in authentication mechanismsPKSA-9qm5-hby2-7bvn CVE-2021-21424 GHSA-5pv8-ppvj-4h68 Affected version: >=5.1.0,<5.2.0|>=5.2.0,<5.2.8 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [HIGH] CVE-2020-5275: All rules set in "access_control" are required when the firewall is configured with the unanimous strategyPKSA-srh1-bn3t-m6gg CVE-2020-5275 GHSA-g4m9-5hpf-hx72 Affected version: >=4.4.0,<4.4.7|>=5.0.0,<5.0.7 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [MEDIUM] CVE-2019-18886: Prevent user enumeration using switch user functionalityPKSA-96vf-z7pm-9yfb CVE-2019-18886 GHSA-4vpc-5jx4-cfqg Affected version: >=4.1.0,<4.2.0|>=4.2.0,<4.2.12|>=4.3.0,<4.3.8 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [HIGH] CVE-2019-10911: Add a separator in the remember me cookie hashPKSA-q3pf-cxf3-f7xy CVE-2019-10911 GHSA-cchx-mfrc-fwqr Affected version: >=2.7.0,<2.7.51|>=2.8.0,<2.8.50|>=3.0.0,<3.1.0|>=3.1.0,<3.2.0|>=3.2.0,<3.3.0|>=3.3.0,<3.4.0|>=3.4.0,<3.4.26|>=4.0.0,<4.1.0|>=4.1.0,<4.1.12|>=4.2.0,<4.2.7 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [MEDIUM] CVE-2018-19790: Open Redirect Vulnerability on loginPKSA-n31d-7jn4-qfx5 CVE-2018-19790 GHSA-89r2-5g34-2g47 Affected version: >=2.7.38,<2.7.50|>=2.8.0,<2.8.49|>=3.0.0,<3.1.0|>=3.1.0,<3.2.0|>=3.2.0,<3.3.0|>=3.3.0,<3.4.0|>=3.4.0,<3.4.20|>=4.0.0,<4.0.15|>=4.1.0,<4.1.9|>=4.2.0,<4.2.1 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [HIGH] CVE-2018-11385: Session Fixation Issue for Guard AuthenticationPKSA-r1pj-t5t2-c1n6 CVE-2018-11385 GHSA-g4rg-rw65-8hfg Affected version: >=2.4.0,<2.7.48|>=2.5.0,<2.7.48|>=2.6.0,<2.7.48|>=2.7.0,<2.7.48|>=2.8.0,<2.8.41|>=3.0.0,<3.1.0|>=3.1.0,<3.2.0|>=3.2.0,<3.3.0|>=3.3.0,<3.3.17|>=3.4.0,<3.4.11|>=4.0.0,<4.0.11 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [HIGH] CVE-2018-11406: CSRF Token FixationPKSA-4cs6-1fmm-cwn2 CVE-2018-11406 GHSA-g4g7-q726-v5hg Affected version: >=2.4.0,<2.7.48|>=2.5.0,<2.7.48|>=2.6.0,<2.7.48|>=2.7.0,<2.7.48|>=2.8.0,<2.8.41|>=3.0.0,<3.1.0|>=3.1.0,<3.2.0|>=3.2.0,<3.3.0|>=3.3.0,<3.3.17|>=3.4.0,<3.4.11|>=4.0.0,<4.0.11 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [MEDIUM] CVE-2017-16652: Open redirect vulnerability on security handlersPKSA-bmrb-mr4g-zmyn CVE-2017-16652 GHSA-r7p7-qr7p-2rrf Affected version: >=2.7.0,<2.7.38|>=2.8.0,<2.8.31|>=3.0.0,<3.1.0|>=3.1.0,<3.2.0|>=3.2.0,<3.2.14|>=3.3.0,<3.3.13 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [HIGH] CVE-2016-4423: Large username storage in sessionPKSA-7y48-mnc1-xvg1 CVE-2016-4423 GHSA-whgv-8cg3-7hcm Affected version: >=2.3.0,<2.3.41|>=2.4.0,<2.5.0|>=2.5.0,<2.6.0|>=2.6.0,<2.7.0|>=2.7.0,<2.7.13|>=2.8.0,<2.8.6|>=3.0.0,<3.0.6 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [LOW] CVE-2015-8124: Session Fixation in the "Remember Me" Login FeaturePKSA-m51r-2nhf-3g41 CVE-2015-8124 GHSA-j5jh-hpr4-h332 Affected version: >=2.4.0,<2.5.0|>=2.5.0,<2.6.0|>=2.6.0,<2.6.12|>=2.7.0,<2.7.7 Reported by: 
 GitHub, FriendsOfPHP/security-advisories
- 
                        [HIGH] CVE-2015-8125: Potential Remote Timing Attack Vulnerability in Security Remember-Me ServicePKSA-5979-1yv4-cw4f CVE-2015-8125 GHSA-g97c-jfx6-xvxh Affected version: >=2.4.0,<2.5.0|>=2.5.0,<2.6.0|>=2.6.0,<2.6.12|>=2.7.0,<2.7.7 Reported by: 
 GitHub, FriendsOfPHP/security-advisories