{"id":"CVE-2018-11407","aliases":["GHSA-35c5-28pg-2qg4"],"url":"https://o3.security/vulnerability/CVE-2018-11407","summary":"Symfony Authentication Bypass","details":"An issue was discovered in the Ldap component in Symfony 2.8.x before 2.8.37, 3.3.x before 3.3.17, 3.4.x before 3.4.7, and 4.0.x before 4.0.7. It allows remote attackers to bypass authentication by logging in with a \"null\" password and valid username, which triggers an unauthenticated bind.  NOTE: this issue exists because of an incomplete fix for CVE-2016-2403.","published":"2018-06-13T16:29:01.047Z","modified":"2026-08-07T15:11:21.750854Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"symfony/security-core","fixedVersion":"2.8.37"},{"ecosystem":"Packagist","name":"symfony/security-core","fixedVersion":"3.3.17"},{"ecosystem":"Packagist","name":"symfony/security-core","fixedVersion":"3.4.7"},{"ecosystem":"Packagist","name":"symfony/security-core","fixedVersion":"4.0.7"},{"ecosystem":"Packagist","name":"symfony/security","fixedVersion":"2.8.37"},{"ecosystem":"Packagist","name":"symfony/security","fixedVersion":"3.3.17"},{"ecosystem":"Packagist","name":"symfony/security","fixedVersion":"3.4.7"},{"ecosystem":"Packagist","name":"symfony/security","fixedVersion":"4.0.7"},{"ecosystem":"Packagist","name":"symfony/symfony","fixedVersion":"2.8.37"},{"ecosystem":"Packagist","name":"symfony/symfony","fixedVersion":"3.3.17"},{"ecosystem":"Packagist","name":"symfony/symfony","fixedVersion":"3.4.7"},{"ecosystem":"Packagist","name":"symfony/symfony","fixedVersion":"4.0.7"}],"fix":{"url":"https://github.com/symfony/symfony/pull/27377","label":"symfony/symfony#27377"},"references":[{"type":"ADVISORY","url":"https://symfony.com/blog/cve-2018-11407-unauthorized-access-on-a-misconfigured-ldap-server-when-using-an-empty-password"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2018-11407"},{"type":"WEB","url":"https://github.com/symfony/symfony/pull/27377"},{"type":"WEB","url":"https://github.com/symfony/symfony/commit/b46fc93785d37ffa5d706a82cd175b33ce8f2934"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/security-core/CVE-2018-11407.yaml"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/security/CVE-2018-11407.yaml"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/symfony/CVE-2018-11407.yaml"},{"type":"PACKAGE","url":"https://github.com/symfony/symfony"},{"type":"WEB","url":"https://symfony.com/cve-2018-11407"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T15:11:21.750854Z"}}