PKSA-hdr7-z345-3h59 Security Advisory
-
[CRITICAL] CVE-2018-11407: Unauthorized access on a misconfigured LDAP server when using an empty password
PKSA-hdr7-z345-3h59 CVE-2018-11407 GHSA-35c5-28pg-2qg4
Affected package: symfony/security
Affected version: >=2.8.0,<2.8.37|>=3.0.0,<3.1.0|>=3.1.0,<3.2.0|>=3.2.0,<3.3.0|>=3.3.0,<3.3.17|>=3.4.0,<3.4.7|>=4.0.0,<4.0.7
Reported by:
GitHub, FriendsOfPHP/security-advisories