Lucene search

K
osvGoogleOSV:CVE-2016-2403
HistoryFeb 07, 2017 - 5:59 p.m.

CVE-2016-2403

2017-02-0717:59:00
Google
osv.dev
2

7.4 High

AI Score

Confidence

Low

0.006 Low

EPSS

Percentile

78.2%

Symfony before 2.8.6 and 3.x before 3.0.6 allows remote attackers to bypass authentication by logging in with an empty password and valid username, which triggers an unauthenticated bind.

7.4 High

AI Score

Confidence

Low

0.006 Low

EPSS

Percentile

78.2%