First published: Mon Jul 17 2017(Updated: )
Certain Symfony products are affected by: Incorrect Access Control. This affects Symfony 2.7.30 and Symfony 2.8.23 and Symfony 3.2.10 and Symfony 3.3.3. The type of exploitation is: remote. The component is: Password validator.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
composer/symfony/security-core | >=2.7.30<2.7.32>=2.8.23<2.8.25>=3.2.10<3.2.12>=3.3.3<3.3.5 | |
composer/symfony/security | >=2.7.30<2.7.32>=2.8.23<2.8.25>=3.2.10<3.2.12>=3.3.3<3.3.5 | |
composer/symfony/symfony | >=2.7.30<2.7.32>=2.8.23<2.8.25>=3.2.10<3.2.12>=3.3.3<3.3.5 | |
SensioLabs Symfony | =2.7.30 | |
SensioLabs Symfony | =2.8.23 | |
SensioLabs Symfony | =3.2.10 | |
SensioLabs Symfony | =3.3.3 | |
composer/symfony/symfony | >=3.3.3<3.3.5 | 3.3.5 |
composer/symfony/symfony | >=3.2.10<3.2.12 | 3.2.12 |
composer/symfony/symfony | >=2.8.23<2.8.25 | 2.8.25 |
composer/symfony/symfony | >=2.7.30<2.7.32 | 2.7.32 |
composer/symfony/security | >=3.3.3<3.3.5 | 3.3.5 |
composer/symfony/security | >=3.2.10<3.2.12 | 3.2.12 |
composer/symfony/security | >=2.8.23<2.8.25 | 2.8.25 |
composer/symfony/security | >=2.7.30<2.7.32 | 2.7.32 |
composer/symfony/security-core | >=3.3.3<3.3.5 | 3.3.5 |
composer/symfony/security-core | >=3.2.10<3.2.12 | 3.2.12 |
composer/symfony/security-core | >=2.8.23<2.8.25 | 2.8.25 |
composer/symfony/security-core | >=2.7.30<2.7.32 | 2.7.32 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2017-11365 is critical.
Symfony 2.7.30, Symfony 2.8.23, Symfony 3.2.10, and Symfony 3.3.3 are affected by CVE-2017-11365.
The type of exploitation for CVE-2017-11365 is remote.
The component affected by CVE-2017-11365 is the Password validator.
To fix CVE-2017-11365, update Symfony to version 2.7.32, 2.8.25, 3.2.12, or 3.3.5.