{"id":"CVE-2013-5750","aliases":[],"url":"https://o3.security/vulnerability/CVE-2013-5750","summary":"FriendsOfSymfony FOSUserBundle denial of service via login form","details":"The login form in the FriendsOfSymfony FOSUserBundle bundle before 1.3.3 for Symfony allows remote attackers to cause a denial of service (CPU consumption) via a long password that triggers an expensive hash computation, as demonstrated by a PBKDF2 computation.","published":"2022-05-17T05:00:37Z","modified":"2024-12-06T05:33:16.697212Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"friendsofsymfony/user-bundle","fixedVersion":"1.2.5"},{"ecosystem":"Packagist","name":"friendsofsymfony/user-bundle","fixedVersion":"1.3.3"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2013-5750"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/friendsofsymfony/user-bundle/CVE-2013-5750.yaml"},{"type":"WEB","url":"https://symfony.com/cve-2013-5750"},{"type":"WEB","url":"http://symfony.com/blog/cve-2013-5750-security-issue-in-fosuserbundle-login-form"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-12-06T05:33:16.697212Z"}}