First published: Mon May 09 2016(Updated: )
CVE-2016-4423: Large username storage in session
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
composer/symfony/security | >=2.3.0<2.3.41>=2.4.0<2.5.0>=2.5.0<2.6.0>=2.6.0<2.7.0>=2.7.0<2.7.13>=2.8.0<2.8.6>=3.0.0<3.0.6 | |
composer/symfony/symfony | >=2.3.0<2.3.41>=2.4.0<2.5.0>=2.5.0<2.6.0>=2.6.0<2.7.0>=2.7.0<2.7.13>=2.8.0<2.8.6>=3.0.0<3.0.6 | |
composer/symfony/security-http | >=2.3.0<2.3.41>=2.4.0<2.5.0>=2.5.0<2.6.0>=2.6.0<2.7.0>=2.7.0<2.7.13>=2.8.0<2.8.6>=3.0.0<3.0.6 | |
composer/symfony/symfony | >=3.0.0<3.0.6 | 3.0.6 |
composer/symfony/symfony | >=2.8.0<2.8.6 | 2.8.6 |
composer/symfony/symfony | >=2.4.0<2.7.13 | 2.7.13 |
composer/symfony/symfony | >=2.3.0<2.3.41 | 2.3.41 |
composer/symfony/security | >=3.0.0<3.0.6 | 3.0.6 |
composer/symfony/security | >=2.8.0<2.8.6 | 2.8.6 |
composer/symfony/security | >=2.4.0<2.7.13 | 2.7.13 |
composer/symfony/security | >=2.3.0<2.3.41 | 2.3.41 |
composer/symfony/security-http | >=3.0.0<3.0.6 | 3.0.6 |
composer/symfony/security-http | >=2.8.0<2.8.6 | 2.8.6 |
composer/symfony/security-http | >=2.4.0<2.7.13 | 2.7.13 |
composer/symfony/security-http | >=2.3.0<2.3.41 | 2.3.41 |
Symfony | <=2.3.40 | |
Symfony | =2.7.0 | |
Symfony | =2.7.1 | |
Symfony | =2.7.2 | |
Symfony | =2.7.3 | |
Symfony | =2.7.4 | |
Symfony | =2.7.5 | |
Symfony | =2.7.6 | |
Symfony | =2.7.7 | |
Symfony | =2.7.8 | |
Symfony | =2.7.9 | |
Symfony | =2.7.10 | |
Symfony | =2.7.11 | |
Symfony | =2.7.12 | |
Symfony | =2.8.0 | |
Symfony | =2.8.1 | |
Symfony | =2.8.2 | |
Symfony | =2.8.3 | |
Symfony | =2.8.4 | |
Symfony | =2.8.5 | |
Symfony | =3.0.0 | |
Symfony | =3.0.1 | |
Symfony | =3.0.2 | |
Symfony | =3.0.3 | |
Symfony | =3.0.4 | |
Symfony | =3.0.5 | |
Debian Linux | =8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-4423 is classified as a moderate severity vulnerability.
To fix CVE-2016-4423, upgrade Symfony to version 2.3.41, 2.7.13, 2.8.6, or 3.0.6 or later.
CVE-2016-4423 affects Symfony versions prior to 2.3.41, 2.7.13, 2.8.6, and 3.0.6.
CVE-2016-4423 is a vulnerability related to large username storage in session management.
There is no public evidence that CVE-2016-4423 is currently being actively exploited.