Session Fixation Affecting symfony/security-http package, versions <2.7.48>=2.8.0, <2.8.41>=3.0.0, <3.3.17>=3.4.0, <3.4.11>=4.0.0, <4.0.11


Severity

Recommended
0.0
high
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.51% (78th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PHP-SYMFONYSECURITYHTTP-72202
  • published30 May 2018
  • disclosed30 May 2018
  • creditChris Wilkinson

Introduced: 30 May 2018

CVE-2018-11385  (opens in a new tab)
CWE-384  (opens in a new tab)
First added by Snyk

How to fix?

Upgrade symfony/security-http to versions 2.7.48, 2.8.41, 3.3.17, 3.4.11, 4.0.11 or higher.

Overview

symfony/security-http is an HTTP security component for symphony.

Affected versions of this package are vulnerable to Session Fixation via the Guard login feature. An attacker may be able to impersonate the victim towards the web application if the session id value was previously known to the attacker. This allows the attacker to access a Symfony web application with the attacked user's permissions.

Note:

  • The Guard authentication login feature must be enabled for the attack to be applicable.
  • The attacker must have access to the PHPSESSID cookie value or has successfully set a new value in the user's browser.

CVSS Scores

version 3.1