An issue was discovered in Symfony 4.2.0 to 4.2.11 and 4.3.0 to 4.3.7. The ability to enumerate users was possible due to different handling depending on whether the user existed when making unauthorized attempts to use the switch users functionality. This is related to symfony/security.
{ "ubuntu_priority": "low", "availability": "No subscription required", "binaries": [ { "binary_name": "php-symfony", "binary_version": "4.3.8+dfsg-1ubuntu1" }, { "binary_name": "php-symfony-amazon-mailer", "binary_version": "4.3.8+dfsg-1ubuntu1" }, { "binary_name": "php-symfony-asset", "binary_version": "4.3.8+dfsg-1ubuntu1" }, { "binary_name": "php-symfony-browser-kit", "binary_version": "4.3.8+dfsg-1ubuntu1" }, { "binary_name": "php-symfony-cache", "binary_version": "4.3.8+dfsg-1ubuntu1" }, { "binary_name": "php-symfony-config", "binary_version": "4.3.8+dfsg-1ubuntu1" }, { "binary_name": "php-symfony-console", "binary_version": "4.3.8+dfsg-1ubuntu1" }, { "binary_name": "php-symfony-css-selector", "binary_version": "4.3.8+dfsg-1ubuntu1" }, { "binary_name": "php-symfony-debug", "binary_version": "4.3.8+dfsg-1ubuntu1" }, { "binary_name": "php-symfony-debug-bundle", "binary_version": "4.3.8+dfsg-1ubuntu1" }, { "binary_name": "php-symfony-dependency-injection", "binary_version": "4.3.8+dfsg-1ubuntu1" }, { "binary_name": "php-symfony-doctrine-bridge", "binary_version": "4.3.8+dfsg-1ubuntu1" }, { "binary_name": "php-symfony-dom-crawler", "binary_version": "4.3.8+dfsg-1ubuntu1" }, { "binary_name": "php-symfony-dotenv", "binary_version": "4.3.8+dfsg-1ubuntu1" }, { "binary_name": "php-symfony-event-dispatcher", "binary_version": "4.3.8+dfsg-1ubuntu1" }, { "binary_name": "php-symfony-expression-language", "binary_version": "4.3.8+dfsg-1ubuntu1" }, { "binary_name": "php-symfony-filesystem", "binary_version": "4.3.8+dfsg-1ubuntu1" }, { "binary_name": "php-symfony-finder", "binary_version": "4.3.8+dfsg-1ubuntu1" }, { "binary_name": "php-symfony-form", "binary_version": "4.3.8+dfsg-1ubuntu1" }, { "binary_name": "php-symfony-framework-bundle", "binary_version": "4.3.8+dfsg-1ubuntu1" }, { "binary_name": "php-symfony-google-mailer", "binary_version": "4.3.8+dfsg-1ubuntu1" }, { "binary_name": "php-symfony-http-client", "binary_version": "4.3.8+dfsg-1ubuntu1" }, { "binary_name": "php-symfony-http-foundation", "binary_version": "4.3.8+dfsg-1ubuntu1" }, { "binary_name": "php-symfony-http-kernel", "binary_version": "4.3.8+dfsg-1ubuntu1" }, { "binary_name": "php-symfony-inflector", "binary_version": "4.3.8+dfsg-1ubuntu1" }, { "binary_name": "php-symfony-intl", "binary_version": "4.3.8+dfsg-1ubuntu1" }, { "binary_name": "php-symfony-ldap", "binary_version": "4.3.8+dfsg-1ubuntu1" }, { "binary_name": "php-symfony-lock", "binary_version": "4.3.8+dfsg-1ubuntu1" }, { "binary_name": "php-symfony-mailchimp-mailer", "binary_version": "4.3.8+dfsg-1ubuntu1" }, { "binary_name": "php-symfony-mailer", "binary_version": "4.3.8+dfsg-1ubuntu1" }, { "binary_name": "php-symfony-mailgun-mailer", "binary_version": "4.3.8+dfsg-1ubuntu1" }, { "binary_name": "php-symfony-messenger", "binary_version": "4.3.8+dfsg-1ubuntu1" }, { "binary_name": "php-symfony-mime", "binary_version": "4.3.8+dfsg-1ubuntu1" }, { "binary_name": "php-symfony-monolog-bridge", "binary_version": "4.3.8+dfsg-1ubuntu1" }, { "binary_name": "php-symfony-options-resolver", "binary_version": "4.3.8+dfsg-1ubuntu1" }, { "binary_name": "php-symfony-phpunit-bridge", "binary_version": "4.3.8+dfsg-1ubuntu1" }, { "binary_name": "php-symfony-postmark-mailer", "binary_version": "4.3.8+dfsg-1ubuntu1" }, { "binary_name": "php-symfony-process", "binary_version": "4.3.8+dfsg-1ubuntu1" }, { "binary_name": "php-symfony-property-access", "binary_version": "4.3.8+dfsg-1ubuntu1" }, { "binary_name": "php-symfony-property-info", "binary_version": "4.3.8+dfsg-1ubuntu1" }, { "binary_name": "php-symfony-proxy-manager-bridge", "binary_version": "4.3.8+dfsg-1ubuntu1" }, { "binary_name": "php-symfony-routing", "binary_version": "4.3.8+dfsg-1ubuntu1" }, { "binary_name": "php-symfony-security", "binary_version": "4.3.8+dfsg-1ubuntu1" }, { "binary_name": "php-symfony-security-bundle", "binary_version": "4.3.8+dfsg-1ubuntu1" }, { "binary_name": "php-symfony-security-core", "binary_version": "4.3.8+dfsg-1ubuntu1" }, { "binary_name": "php-symfony-security-csrf", "binary_version": "4.3.8+dfsg-1ubuntu1" }, { "binary_name": "php-symfony-security-guard", "binary_version": "4.3.8+dfsg-1ubuntu1" }, { "binary_name": "php-symfony-security-http", "binary_version": "4.3.8+dfsg-1ubuntu1" }, { "binary_name": "php-symfony-sendgrid-mailer", "binary_version": "4.3.8+dfsg-1ubuntu1" }, { "binary_name": "php-symfony-serializer", "binary_version": "4.3.8+dfsg-1ubuntu1" }, { "binary_name": "php-symfony-stopwatch", "binary_version": "4.3.8+dfsg-1ubuntu1" }, { "binary_name": "php-symfony-templating", "binary_version": "4.3.8+dfsg-1ubuntu1" }, { "binary_name": "php-symfony-translation", "binary_version": "4.3.8+dfsg-1ubuntu1" }, { "binary_name": "php-symfony-twig-bridge", "binary_version": "4.3.8+dfsg-1ubuntu1" }, { "binary_name": "php-symfony-twig-bundle", "binary_version": "4.3.8+dfsg-1ubuntu1" }, { "binary_name": "php-symfony-validator", "binary_version": "4.3.8+dfsg-1ubuntu1" }, { "binary_name": "php-symfony-var-dumper", "binary_version": "4.3.8+dfsg-1ubuntu1" }, { "binary_name": "php-symfony-var-exporter", "binary_version": "4.3.8+dfsg-1ubuntu1" }, { "binary_name": "php-symfony-web-link", "binary_version": "4.3.8+dfsg-1ubuntu1" }, { "binary_name": "php-symfony-web-profiler-bundle", "binary_version": "4.3.8+dfsg-1ubuntu1" }, { "binary_name": "php-symfony-web-server-bundle", "binary_version": "4.3.8+dfsg-1ubuntu1" }, { "binary_name": "php-symfony-workflow", "binary_version": "4.3.8+dfsg-1ubuntu1" }, { "binary_name": "php-symfony-yaml", "binary_version": "4.3.8+dfsg-1ubuntu1" } ] }