-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| symfony/security-http | composer | < 7.1.0 | 7.1.0 |
The vulnerability stemmed from the lack of validation for non-empty credentials in the getCredentials method. The commit a804ca1 introduced checks for empty username/password fields by throwing BadRequestHttpException, confirming the pre-patch code was missing these validations. The function's role in processing login requests makes it the logical point of failure for the described authentication bypass scenario.
Ongoing coverage of React2Shell