Vulnerability Description
An issue was discovered in the Ldap component in Symfony 2.8.x before 2.8.37, 3.3.x before 3.3.17, 3.4.x before 3.4.7, and 4.0.x before 4.0.7. It allows remote attackers to bypass authentication by logging in with a "null" password and valid username, which triggers an unauthenticated bind. NOTE: this issue exists because of an incomplete fix for CVE-2016-2403.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sensiolabs | Symfony | >= 2.8.0, < 2.8.37 |
Related Weaknesses (CWE)
References
- https://symfony.com/blog/cve-2018-11407-unauthorized-access-on-a-misconfigured-lVendor Advisory
- https://symfony.com/blog/cve-2018-11407-unauthorized-access-on-a-misconfigured-lVendor Advisory
FAQ
What is CVE-2018-11407?
CVE-2018-11407 is a vulnerability with a CVSS score of 9.8 (CRITICAL). An issue was discovered in the Ldap component in Symfony 2.8.x before 2.8.37, 3.3.x before 3.3.17, 3.4.x before 3.4.7, and 4.0.x before 4.0.7. It allows remote attackers to bypass authentication by lo...
How severe is CVE-2018-11407?
CVE-2018-11407 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2018-11407?
Check the references section above for vendor advisories and patch information. Affected products include: Sensiolabs Symfony.