User Authentication Vulnerability in Symfony Framework
CVE-2019-10911
7.5HIGH
What is CVE-2019-10911?
A security vulnerability in the Symfony Framework prior to specified versions allows an attacker to authenticate as a privileged user. This issue is primarily associated with sites utilizing user registration and 'remember me' login functionality. The flaw is rooted in the handling of the remember me cookie, compromising the integrity of user sessions. Affected versions include Symfony 2.7 through 2.7.50, 2.8.x through 2.8.49, 3.x through 3.4.25, 4.x through 4.1.11, and 4.2.x through 4.2.6. Mitigation measures should be taken by updating to the latest secure versions to prevent unauthorized access.