CVE-2017-11365: Critical severity SensioLabs Symfony vulnerability
Published Jul 17, 2017
·Updated
Certain Symfony products are affected by: Incorrect Access Control. This affects Symfony 2.7.30 and Symfony 2.8.23 and Symfony 3.2.10 and Symfony 3.3.3. The type of exploitation is: remote. The component is: Password validator.
Other sources
CVE-2017-11365: Empty passwords validation issue
Affected Software
19 affected componentsFixes available
composer/symfony/security-core>=2.7.30, <2.7.32, >=2.8.23, <2.8.25, >=3.2.10, <3.2.12, >=3.3.3, <3.3.5
composer/symfony/security>=2.7.30, <2.7.32, >=2.8.23, <2.8.25, >=3.2.10, <3.2.12, >=3.3.3, <3.3.5
composer/symfony/symfony>=2.7.30, <2.7.32, >=2.8.23, <2.8.25, >=3.2.10, <3.2.12, >=3.3.3, <3.3.5
composer/symfony/symfony>=3.3.3<3.3.5
3.3.5
composer/symfony/symfony>=3.2.10<3.2.12
3.2.12
composer/symfony/symfony>=2.8.23<2.8.25
2.8.25
composer/symfony/symfony>=2.7.30<2.7.32
2.7.32
composer/symfony/security>=3.3.3<3.3.5
3.3.5
composer/symfony/security>=3.2.10<3.2.12
3.2.12
composer/symfony/security>=2.8.23<2.8.25
2.8.25
composer/symfony/security>=2.7.30<2.7.32
2.7.32
composer/symfony/security-core>=3.3.3<3.3.5
3.3.5
composer/symfony/security-core>=3.2.10<3.2.12
3.2.12
composer/symfony/security-core>=2.8.23<2.8.25
2.8.25
composer/symfony/security-core>=2.7.30<2.7.32
2.7.32
SensioLabs Symfony=2.7.30
SensioLabs Symfony=2.8.23
SensioLabs Symfony=3.2.10
SensioLabs Symfony=3.3.3
Remediation
Patch Available
Event History
Jul 17, 2017
Advisory Published
10:54 AM
May 23, 2019
CVE Published
via MITRE·05:20 PM
Data Sourced
via MITRE·05:20 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-11365?
The severity of CVE-2017-11365 is critical.
2
Which Symfony versions are affected by CVE-2017-11365?
Symfony 2.7.30, Symfony 2.8.23, Symfony 3.2.10, and Symfony 3.3.3 are affected by CVE-2017-11365.
3
What is the type of exploitation for CVE-2017-11365?
The type of exploitation for CVE-2017-11365 is remote.
4
What is the component affected by CVE-2017-11365?
The component affected by CVE-2017-11365 is the Password validator.
5
How can I fix CVE-2017-11365?
To fix CVE-2017-11365, update Symfony to version 2.7.32, 2.8.25, 3.2.12, or 3.3.5.