CVE-2024-50341
CVSS 3.1 Score 3.1 of 10 (low)
Details
Summary
CVE-2024-50341 is a vulnerability affecting the symfony/security-bundle module in Symphony PHP framework versions 6.4.10, 7.0.10, and 7.1.3. This module provides security integration into the Symfony full-stack framework. The issue arises when using the `Security::login` method for programmatic login, which bypasses the custom `user_checker` defined on the firewall. This can result in unwanted logins. To mitigate this risk, users are advised to upgrade to the latest versions, which now ensure the `user_checker` is called during programmatic logins. No known workarounds are available for this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.