Vulnerabilities > CVE-2018-11386 - Insufficient Session Expiration vulnerability in multiple products

047910
CVSS 5.9 - MEDIUM
Attack vector
NETWORK
Attack complexity
HIGH
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
HIGH
network
high complexity
sensiolabs
debian
CWE-613
nessus

Summary

An issue was discovered in the HttpFoundation component in Symfony 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x before 4.0.11. The PDOSessionHandler class allows storing sessions on a PDO connection. Under some configurations and with a well-crafted payload, it was possible to do a denial of service on a Symfony application without too much resources.

Vulnerable Configurations

Part Description Count
Application
Sensiolabs
147
OS
Debian
1

Common Weakness Enumeration (CWE)

Nessus

  • NASL familyDebian Local Security Checks
    NASL idDEBIAN_DSA-4262.NASL
    descriptionMultiple vulnerabilities have been found in the Symfony PHP framework which could lead to open redirects, cross-site request forgery, information disclosure, session fixation or denial of service.
    last seen2020-06-01
    modified2020-06-02
    plugin id111535
    published2018-08-06
    reporterThis script is Copyright (C) 2018 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/111535
    titleDebian DSA-4262-1 : symfony - security update
  • NASL familyFedora Local Security Checks
    NASL idFEDORA_2018-EBA0006DF2.NASL
    description**Version 2.8.41** (2018-05-25) - bug #27359 [HttpFoundation] Fix perf issue during MimeTypeGuesser intialization (nicolas-grekas) - security #cve-2018-11408 [SecurityBundle] Fail if security.http_utils cannot be configured - security #cve-2018-11406 clear CSRF tokens when the user is logged out - security #cve-2018-11385 Adding session authentication strategy to Guard to avoid session fixation - security #cve-2018-11385 Adding session strategy to ALL listeners to avoid *any* possible fixation - security #cve-2018-11386 [HttpFoundation] Break infinite loop in PdoSessionHandler when MySQL is in loose mode ---- **Version 2.8.40** (2018-05-21) - bug #26781 [Form] Fix precision of MoneyToLocalizedStringTransformer
    last seen2020-06-05
    modified2019-01-03
    plugin id120881
    published2019-01-03
    reporterThis script is Copyright (C) 2019-2020 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/120881
    titleFedora 28 : php-symfony (2018-eba0006df2)
  • NASL familyFedora Local Security Checks
    NASL idFEDORA_2018-96D770DDC9.NASL
    description**Version 4.0.11** (2018-05-25) - bug #27364 [DI] Fix bad exception on uninitialized references to non-shared services (nicolas-grekas) - bug #27359 [HttpFoundation] Fix perf issue during MimeTypeGuesser intialization (nicolas-grekas) - security #cve-2018-11408 [SecurityBundle] Fail if security.http_utils cannot be configured - security #cve-2018-11406 clear CSRF tokens when the user is logged out - security #cve-2018-11385 migrating session for UsernamePasswordJsonAuthenticationListener - security #cve-2018-11385 Adding session authentication strategy to Guard to avoid session fixation - security #cve-2018-11385 Adding session strategy to ALL listeners to avoid *any* possible fixation - security #cve-2018-11386 [HttpFoundation] Break infinite loop in PdoSessionHandler when MySQL is in loose mode - bug #27341 [WebProfilerBundle] Fixed validator/dump trace CSS (yceruto) - bug #27337 [FrameworkBundle] fix typo in CacheClearCommand (emilielorenzo) ---- **Version 4.0.10** (2018-05-21) - bug #27264 [Validator] Use strict type in URL validator (mimol91) - bug #27267 [DependencyInjection] resolve array env vars (jamesthomasonjr) - bug #26781 [Form] Fix precision of MoneyToLocalizedStringTransformer
    last seen2020-06-05
    modified2019-01-03
    plugin id120636
    published2019-01-03
    reporterThis script is Copyright (C) 2019-2020 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/120636
    titleFedora 28 : php-symfony4 (2018-96d770ddc9)
  • NASL familyFedora Local Security Checks
    NASL idFEDORA_2018-BA0B683C10.NASL
    description**Version 3.4.11** (2018-05-25) - bug #27364 [DI] Fix bad exception on uninitialized references to non-shared services (nicolas-grekas) - bug #27359 [HttpFoundation] Fix perf issue during MimeTypeGuesser intialization (nicolas-grekas) - security #cve-2018-11408 [SecurityBundle] Fail if security.http_utils cannot be configured - security #cve-2018-11406 clear CSRF tokens when the user is logged out - security #cve-2018-11385 migrating session for UsernamePasswordJsonAuthenticationListener - security #cve-2018-11385 Adding session authentication strategy to Guard to avoid session fixation - security #cve-2018-11385 Adding session strategy to ALL listeners to avoid *any* possible fixation - security #cve-2018-11386 [HttpFoundation] Break infinite loop in PdoSessionHandler when MySQL is in loose mode - bug #27341 [WebProfilerBundle] Fixed validator/dump trace CSS (yceruto) - bug #27337 [FrameworkBundle] fix typo in CacheClearCommand (emilielorenzo) ---- **Version 3.4.10** (2018-05-21) - bug #27264 [Validator] Use strict type in URL validator (mimol91) - bug #27267 [DependencyInjection] resolve array env vars (jamesthomasonjr) - bug #26781 [Form] Fix precision of MoneyToLocalizedStringTransformer
    last seen2020-06-05
    modified2019-01-03
    plugin id120738
    published2019-01-03
    reporterThis script is Copyright (C) 2019-2020 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/120738
    titleFedora 28 : php-symfony3 (2018-ba0b683c10)
  • NASL familyFedora Local Security Checks
    NASL idFEDORA_2018-C8DDC44BBB.NASL
    description## 3.3.17 (2018-05-25) - security #cve-2018-11407 [Ldap] cast to string when checking empty passwords - security #cve-2018-11408 [SecurityBundle] Fail if security.http_utils cannot be configured - security #cve-2018-11406 clear CSRF tokens when the user is logged out - security #cve-2018-11385 migrating session for UsernamePasswordJsonAuthenticationListener - security #cve-2018-11386 [HttpFoundation] Break infinite loop in PdoSessionHandler when MySQL is in loose mode Note that Tenable Network Security has extracted the preceding description block directly from the Fedora update system website. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.
    last seen2020-06-05
    modified2018-07-09
    plugin id110952
    published2018-07-09
    reporterThis script is Copyright (C) 2018-2020 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/110952
    titleFedora 27 : php-symfony3 (2018-c8ddc44bbb)
  • NASL familyFedora Local Security Checks
    NASL idFEDORA_2018-2BDFC9DC67.NASL
    description## 2.8.42 (2018-06-25) - bug #27669 [Filesystem] fix file lock on SunOS (fritzmg) - bug #27309 Fix surrogate not using original request (Toflar) - bug #27630 [Validator][Form] Remove BOM in some xlf files (gautierderuette) - bug #27591 [VarDumper] Fix dumping ArrayObject and ArrayIterator instances (nicolas-grekas) - bug #27581 Fix bad method call with guard authentication + session migration (weaverryan) - bug #27452 Avoid migration on stateless firewalls (weaverryan) - bug #27514 [Debug] Pass previous exception to FatalErrorException (pmontoya) - bug #26973 [HttpKernel] Set first trusted proxy as REMOTE_ADDR in InlineFragmentRenderer. (kmadejski) - bug #27303 [Process] Consider
    last seen2020-06-05
    modified2018-07-09
    plugin id110949
    published2018-07-09
    reporterThis script is Copyright (C) 2018-2020 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/110949
    titleFedora 27 : php-symfony (2018-2bdfc9dc67)