CVE-2019-18886: Medium severity symfony vulnerability
An issue was discovered in Symfony 4.2.0 to 4.2.11 and 4.3.0 to 4.3.7. The ability to enumerate users was possible due to different handling depending on whether the user existed when making unauthorized attempts to use the switch users functionality. This is related to symfony/security.
Other sources
CVE-2019-18886: Prevent user enumeration using switch user functionality
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-18886?
CVE-2019-18886 is a vulnerability that allows user enumeration using the switch user functionality in Symfony versions 4.2.0 to 4.2.11 and 4.3.0 to 4.3.7.
What is the severity of CVE-2019-18886?
The severity of CVE-2019-18886 is medium with a CVSS score of 5.3.
How does CVE-2019-18886 affect Symfony?
CVE-2019-18886 affects Symfony versions 4.2.0 to 4.2.11 and 4.3.0 to 4.3.7.
How can I fix CVE-2019-18886?
To fix CVE-2019-18886, update your Symfony installation to version 4.2.12 or 4.3.8 or later.
Where can I find more information about CVE-2019-18886?
You can find more information about CVE-2019-18886 on the Symfony website.