UBUNTU-CVE-2024-36611

Source
https://ubuntu.com/security/CVE-2024-36611
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-36611.json
JSON Data
https://api.test.osv.dev/v1/vulns/UBUNTU-CVE-2024-36611
Related
Published
2024-11-29T19:15:00Z
Modified
2025-02-04T04:33:58Z
Summary
[none]
Details

In Symfony v7.07, a security vulnerability was identified in the FormLoginAuthenticator component, where it failed to adequately handle cases where the username or password field of a login request is empty. This flaw could lead to various security risks, including improper authentication logic handling or denial of service. NOTE: the Supplier has concluded that this is a false report.

References

Affected packages

Ubuntu:Pro:16.04:LTS / symfony

Package

Name
symfony
Purl
pkg:deb/ubuntu/symfony@2.7.10-0ubuntu2?arch=source&distro=esm-apps/xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*

2.7.1+dfsg-1
2.7.5+dfsg-1
2.7.9+dfsg-1
2.7.9+dfsg-1ubuntu2
2.7.10-0ubuntu2

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:Pro:18.04:LTS / symfony

Package

Name
symfony
Purl
pkg:deb/ubuntu/symfony@3.4.6+dfsg-1ubuntu0.1+esm2?arch=source&distro=esm-apps/bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*

2.8.7+dfsg-1.3ubuntu1

3.*

3.4.3+dfsg-1ubuntu4
3.4.6+dfsg-1
3.4.6+dfsg-1ubuntu0.1
3.4.6+dfsg-1ubuntu0.1+esm1
3.4.6+dfsg-1ubuntu0.1+esm2

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:20.04:LTS / symfony

Package

Name
symfony
Purl
pkg:deb/ubuntu/symfony@4.3.8+dfsg-1ubuntu1?arch=source&distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

4.*

4.3.4+dfsg-1ubuntu1
4.3.8+dfsg-1ubuntu1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:22.04:LTS / symfony

Package

Name
symfony
Purl
pkg:deb/ubuntu/symfony@5.4.4+dfsg-1ubuntu8?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

5.*

5.2.6+dfsg-1ubuntu7
5.4.4+dfsg-1ubuntu8

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:24.10 / symfony

Package

Name
symfony
Purl
pkg:deb/ubuntu/symfony@6.4.10+dfsg-1ubuntu1?arch=source&distro=oracular

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

6.*

6.4.5+dfsg-3ubuntu3
6.4.10+dfsg-1ubuntu1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:24.04:LTS / symfony

Package

Name
symfony
Purl
pkg:deb/ubuntu/symfony@6.4.5+dfsg-3ubuntu3?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

5.*

5.4.23+dfsg-1ubuntu1
5.4.35+dfsg-3ubuntu1

6.*

6.4.5+dfsg-3ubuntu2
6.4.5+dfsg-3ubuntu3

Ecosystem specific

{
    "ubuntu_priority": "medium"
}