CVE-2018-11406
Last modified
CVE-2018-11406 is a vulnerability of currently unknown severity. An issue was discovered in the Security component in Symfony 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x before 4.0.11. By default, a user's session is invalidated when the user is logged out. EPSS estimates a 0.76% chance of exploitation in the next 30 days.
Description
An issue was discovered in the Security component in Symfony 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x before 4.0.11. By default, a user's session is invalidated when the user is logged out. This behavior can be disabled through the invalidate_session option. In this case, CSRF tokens were not erased during logout which allowed for CSRF token fixation.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Sensiolabs | Symfony | >= 2.7.0, < 2.7.48 |
| Sensiolabs | Symfony | >= 2.8.0, < 2.8.41 |
| Sensiolabs | Symfony | >= 3.3.0, < 3.3.17 |
| Sensiolabs | Symfony | >= 3.4.0, < 3.4.11 |
| Sensiolabs | Symfony | >= 4.0.0, < 4.0.11 |
| Debian | Debian Linux | 9.0 |
References
- https://symfony.com/blog/cve-2018-11406-csrf-token-fixationVendor Advisory
- https://www.debian.org/security/2018/dsa-4262Third Party Advisory
- https://symfony.com/blog/cve-2018-11406-csrf-token-fixationVendor Advisory
- https://www.debian.org/security/2018/dsa-4262Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-11406?
How severe is CVE-2018-11406?
How do I fix CVE-2018-11406?
Are you affected by CVE-2018-11406?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
