Lucene search

K
ubuntucveUbuntu.comUB:CVE-2022-24895
HistoryFeb 03, 2023 - 12:00 a.m.

CVE-2022-24895

2023-02-0300:00:00
ubuntu.com
ubuntu.com
14
symfony
php
framework
session id
regeneration
csrf
vulnerability
fix
4.4 branch

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS

0.002

Percentile

54.0%

Symfony is a PHP framework for web and console applications and a set of
reusable PHP components. When authenticating users Symfony by default
regenerates the session ID upon login, but preserves the rest of session
attributes. Because this does not clear CSRF tokens upon login, this might
enables same-site attackers to bypass the CSRF protection mechanism by
performing an attack similar to a session-fixation. This issue has been
fixed in the 4.4 branch.

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS

0.002

Percentile

54.0%