Lucene search

K
symfonySymfony SASSYMFONY:CVE-2019-18886-PREVENT-USER-ENUMERATION-USING-SWITCH-USER-FUNCTIONALITY
HistoryNov 13, 2019 - 12:00 a.m.

CVE-2019-18886: Prevent user enumeration using switch user functionality

2019-11-1300:00:00
Symfony SAS
symfony.com
5

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

AI Score

5.3

Confidence

High

EPSS

0.002

Percentile

53.6%

Affected versions

Symfony 4.2.0 to 4.2.11 and 4.3.0 to 4.3.7 versions of the Symfony Security/Http component are affected by this security issue.

The issue has been fixed in Symfony 4.2.12 and 4.3.8.

Note that no fixes are provided for Symfony 4.1 as they are not maintained anymore.

Description

The ability to enumerate users was possible without relevant permissions due to different handling depending on whether the user existed or not when attempting to use the switch users functionality.

Resolution

We now ensure that 403s are returned whether the user exists or not if a user cannot switch to a user or if the user does not exist.

The patch for this issue is available here for branch 4.2.

Credits

I would like to thank Matt Daum for reporting & Nicolas Grekas for fixing the issue.

Log in to add a reaction to this post

add a reaction ❤️ 👍 🚀

Published in #Security Advisories

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

AI Score

5.3

Confidence

High

EPSS

0.002

Percentile

53.6%

Related for SYMFONY:CVE-2019-18886-PREVENT-USER-ENUMERATION-USING-SWITCH-USER-FUNCTIONALITY