← Back

CVE-2015-8125

nvd nist
Published: Dec 7, 2015Modified: May 6, 2026

JSON object

Loading...
7.5
Vector
AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploitability: 10.0 / Impact: 6.4
Source: NVD

Description

Symfony 2.3.x before 2.3.35, 2.6.x before 2.6.12, and 2.7.x before 2.7.7 might allow remote attackers to have unspecified impact via a timing attack involving the (1) Symfony/Component/Security/Http/RememberMe/PersistentTokenBasedRememberMeServices or (2) Symfony/Component/Security/Http/Firewall/DigestAuthenticationListener class in the Symfony Security Component, or (3) legacy CSRF implementation from the Symfony/Component/Form/Extension/Csrf/CsrfProvider/DefaultCsrfProvider class in the Symfony Form component.

Affected (54)

Products: Sensiolabs: Symfony
1 product
Symfony
Configuration A
54 vulnerable
Vulnerable SoftwareAffected Versions
Sensiolabs
Version 2.3.0
Version 2.3.10
Version 2.3.11
Version 2.3.12
Version 2.3.13
Version 2.3.14
Version 2.3.15
Version 2.3.16
Version 2.3.17
Version 2.3.18
Version 2.3.19
Version 2.3.1
Version 2.3.20
Version 2.3.21
Version 2.3.22
Version 2.3.23
Version 2.3.24
Version 2.3.25
Version 2.3.26
Version 2.3.27
Version 2.3.28
Version 2.3.29
Version 2.3.2
Version 2.3.30
Version 2.3.31
Version 2.3.32
Version 2.3.33
Version 2.3.34
Version 2.3.3
Version 2.3.4
Version 2.3.5
Version 2.3.6
Version 2.3.7
Version 2.3.8
Version 2.3.9
Version 2.6.0
Version 2.6.10
Version 2.6.11
Version 2.6.1
Version 2.6.2
Version 2.6.3
Version 2.6.4
Version 2.6.5
Version 2.6.6
Version 2.6.7
Version 2.6.8
Version 2.6.9
Version 2.7.0
Version 2.7.1
Version 2.7.2
Version 2.7.3
Version 2.7.4
Version 2.7.5
Version 2.7.6

Timeline

No history available yet.