{"id":"CVE-2019-10911","aliases":["GHSA-cchx-mfrc-fwqr"],"url":"https://o3.security/vulnerability/CVE-2019-10911","summary":"Improper authentication in Symfony","details":"In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, a vulnerability would allow an attacker to authenticate as a privileged user on sites with user registration and remember me login functionality enabled. This is related to symfony/security.","published":"2019-05-16T22:29:00.500Z","modified":"2026-08-07T14:48:28.957677Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"Packagist","name":"symfony/security-http","fixedVersion":"2.7.51"},{"ecosystem":"Packagist","name":"symfony/security-http","fixedVersion":"2.8.50"},{"ecosystem":"Packagist","name":"symfony/security-http","fixedVersion":"3.4.26"},{"ecosystem":"Packagist","name":"symfony/security-http","fixedVersion":"4.1.12"},{"ecosystem":"Packagist","name":"symfony/security-http","fixedVersion":"4.2.7"},{"ecosystem":"Packagist","name":"symfony/security","fixedVersion":"2.7.51"},{"ecosystem":"Packagist","name":"symfony/security","fixedVersion":"2.8.50"},{"ecosystem":"Packagist","name":"symfony/security","fixedVersion":"3.4.26"},{"ecosystem":"Packagist","name":"symfony/security","fixedVersion":"4.1.12"},{"ecosystem":"Packagist","name":"symfony/security","fixedVersion":"4.2.7"},{"ecosystem":"Packagist","name":"symfony/symfony","fixedVersion":"2.7.51"},{"ecosystem":"Packagist","name":"symfony/symfony","fixedVersion":"2.8.50"},{"ecosystem":"Packagist","name":"symfony/symfony","fixedVersion":"3.4.26"},{"ecosystem":"Packagist","name":"symfony/symfony","fixedVersion":"4.1.12"},{"ecosystem":"Packagist","name":"symfony/symfony","fixedVersion":"4.2.7"}],"fix":{"url":"https://github.com/symfony/symfony/commit/a29ce2817cf43bb1850cf6af114004ac26c7a081","label":"symfony/symfony@a29ce28"},"references":[{"type":"ADVISORY","url":"https://symfony.com/blog/cve-2019-10911-add-a-separator-in-the-remember-me-cookie-hash"},{"type":"ADVISORY","url":"https://www.synology.com/security/advisory/Synology_SA_19_19"},{"type":"FIX","url":"https://github.com/symfony/symfony/commit/a29ce2817cf43bb1850cf6af114004ac26c7a081"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T14:48:28.957677Z"}}