CVE-2016-2403

Source
https://cve.org/CVERecord?id=CVE-2016-2403
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2016-2403.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2016-2403
Aliases
Downstream
Published
2017-02-07T17:59:00.303Z
Modified
2026-05-15T12:01:31.005861680Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

Symfony before 2.8.6 and 3.x before 3.0.6 allows remote attackers to bypass authentication by logging in with an empty password and valid username, which triggers an unauthenticated bind.

References

Affected packages