First published: Mon May 09 2016(Updated: )
CVE-2016-2403: Unauthorized access on a misconfigured Ldap server when using an empty password
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
composer/symfony/symfony | >=2.8.0<2.8.6>=3.0.0<3.0.6 | |
composer/symfony/security-core | >=2.8.0<2.8.6>=3.0.0<3.0.6 | |
composer/symfony/security | >=2.8.0<2.8.6>=3.0.0<3.0.6 | |
debian/symfony | 3.4.22+dfsg-2+deb10u1 3.4.22+dfsg-2+deb10u2 4.4.19+dfsg-2+deb11u3 5.4.23+dfsg-1 5.4.29+dfsg-1 5.4.30+dfsg-1 | |
composer/symfony/symfony | >=3.0.0<3.0.6 | 3.0.6 |
composer/symfony/symfony | >=2.8.0<2.8.6 | 2.8.6 |
composer/symfony/security | >=3.0.0<3.0.6 | 3.0.6 |
composer/symfony/security | >=2.8.0<2.8.6 | 2.8.6 |
composer/symfony/security-core | >=3.0.0<3.0.6 | 3.0.6 |
composer/symfony/security-core | >=2.8.0<2.8.6 | 2.8.6 |
Symfony | =2.8.0 | |
Symfony | =2.8.1 | |
Symfony | =2.8.2 | |
Symfony | =2.8.3 | |
Symfony | =2.8.4 | |
Symfony | =2.8.5 | |
Symfony | =3.0.0 | |
Symfony | =3.0.1 | |
Symfony | =3.0.2 | |
Symfony | =3.0.3 | |
Symfony | =3.0.4 | |
Symfony | =3.0.5 | |
=2.8.0 | ||
=2.8.1 | ||
=2.8.2 | ||
=2.8.3 | ||
=2.8.4 | ||
=2.8.5 | ||
=3.0.0 | ||
=3.0.1 | ||
=3.0.2 | ||
=3.0.3 | ||
=3.0.4 | ||
=3.0.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-2403 is classified as a critical vulnerability due to its potential to allow unauthorized access.
To remediate CVE-2016-2403, upgrade Symfony to version 2.8.6 or 3.0.6 or later.
CVE-2016-2403 affects Symfony versions 2.8.0 through 2.8.6 and 3.0.0 through 3.0.6.
CVE-2016-2403 presents a security risk of unauthorized access, allowing attackers to authenticate with empty passwords.
Yes, CVE-2016-2403 specifically affects the Symfony framework versions mentioned.