CVE-2016-2403
07.02.2017, 17:59
Symfony before 2.8.6 and 3.x before 3.0.6 allows remote attackers to bypass authentication by logging in with an empty password and valid username, which triggers an unauthenticated bind.Enginsight
| Vendor | Product | Version |
|---|---|---|
| sensiolabs | symfony | 2.8.0 |
| sensiolabs | symfony | 2.8.1 |
| sensiolabs | symfony | 2.8.2 |
| sensiolabs | symfony | 2.8.3 |
| sensiolabs | symfony | 2.8.4 |
| sensiolabs | symfony | 2.8.5 |
| sensiolabs | symfony | 3.0.0 |
| sensiolabs | symfony | 3.0.1 |
| sensiolabs | symfony | 3.0.2 |
| sensiolabs | symfony | 3.0.3 |
| sensiolabs | symfony | 3.0.4 |
| sensiolabs | symfony | 3.0.5 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Common Weakness Enumeration
References