An issue was discovered in the Ldap component in Symfony 2.8.x before 2.8.37, 3.3.x before 3.3.17, 3.4.x before 3.4.7, and 4.0.x before 4.0.7. It allows remote attackers to bypass authentication by logging in with a "null" password and valid username, which triggers an unauthenticated bind. NOTE: this issue exists because of an incomplete fix for CVE-2016-2403.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2018-06-13T16:00:00

Updated: 2018-06-13T15:57:01

Reserved: 2018-05-24T00:00:00


Link: CVE-2018-11407

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2018-06-13T16:29:01.047

Modified: 2018-08-03T12:45:41.383


Link: CVE-2018-11407

JSON object: View

cve-icon Redhat Information

No data.

CWE