CVE-2015-8125: CSRF
CVE-2015-8125: Potential Remote Timing Attack Vulnerability in Security Remember-Me Service
Other sources
Symfony 2.3.x before 2.3.35, 2.6.x before 2.6.12, and 2.7.x before 2.7.7 might allow remote attackers to have unspecified impact via a timing attack involving the (1) Symfony/Component/Security/Http/RememberMe/PersistentTokenBasedRememberMeServices or (2) Symfony/Component/Security/Http/Firewall/DigestAuthenticationListener class in the Symfony Security Component, or (3) legacy CSRF implementation from the Symfony/Component/Form/Extension/Csrf/CsrfProvider/DefaultCsrfProvider class in the Symfony Form component.
Symfony 2.3.x before 2.3.35, 2.6.x before 2.6.12, and 2.7.x before 2.7.7 might allow remote attackers to have unspecified impact via a timing attack involving the (1) Symfony/Component/Security/Http/RememberMe/PersistentTokenBasedRememberMeServices or (2) Symfony/Component/Security/Http/Firewall/DigestAuthenticationListener class in the Symfony Security Component, or (3) legacy CSRF implementation from the Symfony/Component/Form/Extension/Csrf/CsrfProvider/DefaultCsrfProvider class in the Symfony Form component.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2015-8125?
CVE-2015-8125 has been assigned a moderate severity level due to its potential for remote timing attacks.
How do I fix CVE-2015-8125?
To fix CVE-2015-8125, upgrade to Symfony versions 2.3.35, 2.6.12, or 2.7.7 or later.
What versions are affected by CVE-2015-8125?
CVE-2015-8125 affects Symfony versions 2.3.x before 2.3.35, 2.6.x before 2.6.12, and 2.7.x before 2.7.7.
Is CVE-2015-8125 a hardware or software vulnerability?
CVE-2015-8125 is a software vulnerability found in the Symfony framework.
What impact can CVE-2015-8125 have on my application?
CVE-2015-8125 may allow remote attackers to exploit timing attack vulnerabilities, potentially compromising the security of the application.