CVE-2024-51996: Authentication Bypass via persisted RememberMe cookie

Affected versions

Symfony versions >=5.3, <5.4.47; >=6, <6.4.15; >=7, <7.1.8 of the Symfony Security-Http component are affected by this security issue.

The issue has been fixed in Symfony 5.4.47, 6.4.15, and 7.1.8.

Description

Whan consuming… https://symfony.com/blog/cve-2024-51996-authentication-bypass-via-persisted-rememberme-cookie?utm_source=Symfony%20Blog%20Feed&utm_medium=feed

Created 2d | Nov 13, 2024, 4:50:04 PM


Login to add comment

Other posts in this group

New in Symfony 7.2: Redesigned TypeInfo Component

Contributed by Mathias Arlaud in

Nov 15, 2024, 10:30:25 AM | Symfony
SymfonyOnline January 2025 is coming up soon - join us online!

SymfonyOnline January 2025 is coming up soon, running on January 16-17, and it’s going to be a great two-day online conference! Get ready for top-notch insights, inspiring schedule & speake

Nov 14, 2024, 6:21:35 PM | Symfony
New in Symfony 7.2: New Command Options

In Symfony 7.2, we've improved many existing commands with new options and features.

Resolve Env Vars when Linting the Container

Nov 14, 2024, 11:20:23 AM | Symfony
Symfony 7.1.8 released

Symfony 7.1.8 has just been released. Here is the list of the most important changes since 7.1.7:

security #cve-2024-50342 [HttpClient] Resolve hostnames in NoPrivateNetworkHttpClient (@nicolas-g
Nov 13, 2024, 4:50:05 PM | Symfony
Update for CVE-2024-50342: Internal address and port enumeration allowed by NoPrivateNetworkHttpClient

The patch released last week for CVE-2024-50342 was incomplete. New versions have just been released to address it. https://symfony.com/blog/update-for-cve-2024-50342-internal-address-and-port-enumera

Nov 13, 2024, 4:50:03 PM | Symfony
Symfony 7.2.0-RC1 released

Symfony 7.2.0-RC1 has just been released. Here is the list of the most important changes since 7.2.0-BETA2:

feature #58852 [TypeInfo] Remove @experimental tag (@mtarld)

feature #57630 [TypeInfo]

Nov 13, 2024, 4:50:02 PM | Symfony
Symfony 5.4.47 released

Symfony 5.4.47 has just been released. Here is the list of the most important changes since 5.4.46:

security #cve-2024-50342 [HttpClient] Resolve hostnames in NoPrivateNetworkHttpClient (@nicolas
Nov 13, 2024, 2:30:32 PM | Symfony