-
CVSS Score
-The vulnerability stems from missing empty password validation in LDAP authentication flow. The security advisory and Symfony blog explicitly state the fix added password presence checking. The LdapClient::bind() method is the logical location for this authentication primitive in Symfony's security component. This function would appear in stack traces during authentication attempts with empty passwords in vulnerable versions.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| symfony/security-core | composer | >= 2.8.0, < 2.8.6 | 2.8.6 |
| symfony/security-core | composer | >= 3.0.0, < 3.0.6 | 3.0.6 |
| symfony/security | composer | >= 2.8.0, < 2.8.6 | 2.8.6 |
| symfony/security | composer | >= 3.0.0, < 3.0.6 | 3.0.6 |
| symfony/symfony | composer | >= 2.8.0, < 2.8.6 | 2.8.6 |
| symfony/symfony | composer | >= 3.0.0, < 3.0.6 | 3.0.6 |
A Semantic Attack on Google Gemini - Read the Latest Research