7.5
CVSSv2

CVE-2015-8125

Published: 07/12/2015 Updated: 07/12/2016
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Symfony 2.3.x prior to 2.3.35, 2.6.x prior to 2.6.12, and 2.7.x prior to 2.7.7 might allow remote malicious users to have unspecified impact via a timing attack involving the (1) Symfony/Component/Security/Http/RememberMe/PersistentTokenBasedRememberMeServices or (2) Symfony/Component/Security/Http/Firewall/DigestAuthenticationListener class in the Symfony Security Component, or (3) legacy CSRF implementation from the Symfony/Component/Form/Extension/Csrf/CsrfProvider/DefaultCsrfProvider class in the Symfony Form component.

Vulnerable Product Search on Vulmon Subscribe to Product

sensiolabs symfony 2.3.6

sensiolabs symfony 2.3.7

sensiolabs symfony 2.3.14

sensiolabs symfony 2.3.15

sensiolabs symfony 2.3.22

sensiolabs symfony 2.3.23

sensiolabs symfony 2.3.31

sensiolabs symfony 2.3.32

sensiolabs symfony 2.6.4

sensiolabs symfony 2.6.5

sensiolabs symfony 2.7.0

sensiolabs symfony 2.7.1

sensiolabs symfony 2.3.3

sensiolabs symfony 2.3.4

sensiolabs symfony 2.3.5

sensiolabs symfony 2.3.12

sensiolabs symfony 2.3.13

sensiolabs symfony 2.3.20

sensiolabs symfony 2.3.21

sensiolabs symfony 2.3.29

sensiolabs symfony 2.3.30

sensiolabs symfony 2.6.2

sensiolabs symfony 2.6.3

sensiolabs symfony 2.6.10

sensiolabs symfony 2.6.11

sensiolabs symfony 2.3.0

sensiolabs symfony 2.3.8

sensiolabs symfony 2.3.9

sensiolabs symfony 2.3.16

sensiolabs symfony 2.3.17

sensiolabs symfony 2.3.24

sensiolabs symfony 2.3.25

sensiolabs symfony 2.3.33

sensiolabs symfony 2.3.34

sensiolabs symfony 2.6.6

sensiolabs symfony 2.6.7

sensiolabs symfony 2.7.2

sensiolabs symfony 2.7.3

sensiolabs symfony 2.7.4

sensiolabs symfony 2.3.1

sensiolabs symfony 2.3.2

sensiolabs symfony 2.3.10

sensiolabs symfony 2.3.11

sensiolabs symfony 2.3.18

sensiolabs symfony 2.3.19

sensiolabs symfony 2.3.26

sensiolabs symfony 2.3.27

sensiolabs symfony 2.3.28

sensiolabs symfony 2.6.0

sensiolabs symfony 2.6.1

sensiolabs symfony 2.6.8

sensiolabs symfony 2.6.9

sensiolabs symfony 2.7.5

sensiolabs symfony 2.7.6

Vendor Advisories

Several vulnerabilities have been discovered in symfony, a framework to create websites and web applications The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2015-8124 The RedTeam Pentesting GmbH team discovered a session fixation vulnerability within the Remember Me login feature, allowing an at ...