User Enumeration Vulnerability in Symfony Framework by Symfony
CVE-2019-18886
5.3MEDIUM
Summary
A user enumeration vulnerability was identified in Symfony that affects versions 4.2.0 through 4.2.11 and 4.3.0 through 4.3.7. This flaw arises from inconsistent behavior during unauthorized attempts to use the switch user functionality, allowing attackers to discern whether a user exists based on the system's responses. This could potentially enable malicious actors to gain insights into user accounts within a vulnerable application, compromising the integrity and security of the system. It is crucial for developers using Symfony to upgrade to the latest versions to mitigate this risk.
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved