User Enumeration Vulnerability in Symfony Framework by Symfony
CVE-2019-18886
What is CVE-2019-18886?
A user enumeration vulnerability was identified in Symfony that affects versions 4.2.0 through 4.2.11 and 4.3.0 through 4.3.7. This flaw arises from inconsistent behavior during unauthorized attempts to use the switch user functionality, allowing attackers to discern whether a user exists based on the system's responses. This could potentially enable malicious actors to gain insights into user accounts within a vulnerable application, compromising the integrity and security of the system. It is crucial for developers using Symfony to upgrade to the latest versions to mitigate this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
