CVE Database
/

CVE-2015-8125

Back to search

CVE-2015-8125

Published: Dec 7, 2015

Modified: Aug 6, 2024

PUBLISHED

Description

Symfony 2.3.x before 2.3.35, 2.6.x before 2.6.12, and 2.7.x before 2.7.7 might allow remote attackers to have unspecified impact via a timing attack involving the (1) Symfony/Component/Security/Http/RememberMe/PersistentTokenBasedRememberMeServices or (2) Symfony/Component/Security/Http/Firewall/DigestAuthenticationListener class in the Symfony Security Component, or (3) legacy CSRF implementation from the Symfony/Component/Form/Extension/Csrf/CsrfProvider/DefaultCsrfProvider class in the Symfony Form component.

VendorProductVersions

n/a

n/a

affected
n/a

References

FEDORA-2015-0efcb5fbc5
vendor-advisory
x_refsource_FEDORA
FEDORA-2015-0b89738311
vendor-advisory
x_refsource_FEDORA
DSA-3402
vendor-advisory
x_refsource_DEBIAN
77692
vdb-entry
x_refsource_BID

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now