CVE-2018-11407: Critical severity symfony vulnerability
An issue was discovered in the LDAP component in Symfony 2.8.x before 2.8.37, 3.3.x before 3.3.17, 3.4.x before 3.4.7, and 4.0.x before 4.0.7. It allows remote attackers to bypass authentication by logging in with a "null" password and valid username, which triggers an unauthenticated bind. NOTE: this issue exists because of an incomplete fix for CVE-2016-2403.
Other sources
An issue was discovered in the Ldap component in Symfony 2.8.x before 2.8.37, 3.3.x before 3.3.17, 3.4.x before 3.4.7, and 4.0.x before 4.0.7. It allows remote attackers to bypass authentication by logging in with a "null" password and valid username, which triggers an unauthenticated bind. NOTE: this issue exists because of an incomplete fix for CVE-2016-2403.
CVE-2018-11407: Unauthorized access on a misconfigured LDAP server when using an empty password
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-11407?
CVE-2018-11407 is a vulnerability in the Ldap component in Symfony that allows unauthorized access on a misconfigured LDAP server when using an empty password.
What is the severity level of CVE-2018-11407?
The Severity level of CVE-2018-11407 is critical with a score of 9.8 out of 10.
Which software versions are affected by CVE-2018-11407?
CVE-2018-11407 affects Symfony versions 2.8.x, 3.3.x, 3.4.x, and 4.0.x.
How can unauthorized access be bypassed in CVE-2018-11407?
Unauthorized access can be bypassed in CVE-2018-11407 by logging in with a "null" password and valid username, which triggers an unauthenticated bind.
Where can I find more information about CVE-2018-11407?
You can find more information about CVE-2018-11407 on the Symfony website.