-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability stemmed from a regression introduced in #23341 where empty password handling was modified. The security patch adds an explicit violation for empty passwords (null or '') in UserPasswordValidator.php. This indicates the original vulnerability existed in the validate() method's handling of empty values before the patch, allowing potential authentication bypass when empty passwords weren't properly validated against stored credentials.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| symfony/security-core | composer | >= 2.7.30, < 2.7.32 | 2.7.32 |
| symfony/security-core | composer | >= 2.8.23, < 2.8.25 | 2.8.25 |
| symfony/security-core |
| composer |
| >= 3.2.10, < 3.2.12 |
| 3.2.12 |
| symfony/security-core | composer | >= 3.3.3, < 3.3.5 | 3.3.5 |
| symfony/security | composer | >= 2.7.30, < 2.7.32 | 2.7.32 |
| symfony/security | composer | >= 2.8.23, < 2.8.25 | 2.8.25 |
| symfony/security | composer | >= 3.2.10, < 3.2.12 | 3.2.12 |
| symfony/security | composer | >= 3.3.3, < 3.3.5 | 3.3.5 |
| symfony/symfony | composer | >= 2.7.30, < 2.7.32 | 2.7.32 |
| symfony/symfony | composer | >= 2.8.23, < 2.8.25 | 2.8.25 |
| symfony/symfony | composer | >= 3.2.10, < 3.2.12 | 3.2.12 |
| symfony/symfony | composer | >= 3.3.3, < 3.3.5 | 3.3.5 |
Ongoing coverage of React2Shell