Session Fixation Affecting symfony/symfony package, versions >=5.4.21, <5.4.31 >=6.2.7, <6.3.8
Threat Intelligence
EPSS
0.11% (45th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-PHP-SYMFONYSYMFONY-6056135
- published 12 Nov 2023
- disclosed 10 Nov 2023
- credit Robert Meijers
Introduced: 10 Nov 2023
CVE-2023-46733 Open this link in a new tabHow to fix?
Upgrade symfony/symfony
to version 5.4.31, 6.3.8 or higher.
Overview
symfony/symfony is a PHP framework for web applications and a set of reusable PHP components.
Affected versions of this package are vulnerable to Session Fixation in the SessionStrategyListener
, when the user identifier doesn't change between the verification phase and the successful login, while the token itself changes from one type (partially-authenticated) to another (fully-authenticated).
References
CVSS Scores
version 3.1