Vulnerability Description
Symfony before 2.8.6 and 3.x before 3.0.6 allows remote attackers to bypass authentication by logging in with an empty password and valid username, which triggers an unauthenticated bind.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sensiolabs | Symfony | 2.8.0 |
Related Weaknesses (CWE)
References
- http://symfony.com/blog/cve-2016-2403-unauthorized-access-on-a-misconfigured-ldaVendor Advisory
- http://www.securityfocus.com/bid/96137Third Party AdvisoryVDB Entry
- https://www.debian.org/security/2018/dsa-4262
- http://symfony.com/blog/cve-2016-2403-unauthorized-access-on-a-misconfigured-ldaVendor Advisory
- http://www.securityfocus.com/bid/96137Third Party AdvisoryVDB Entry
- https://www.debian.org/security/2018/dsa-4262
FAQ
What is CVE-2016-2403?
CVE-2016-2403 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Symfony before 2.8.6 and 3.x before 3.0.6 allows remote attackers to bypass authentication by logging in with an empty password and valid username, which triggers an unauthenticated bind.
How severe is CVE-2016-2403?
CVE-2016-2403 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2016-2403?
Check the references section above for vendor advisories and patch information. Affected products include: Sensiolabs Symfony.