{"id":"CVE-2024-50341","summary":"Security::login does not take into account custom user_checker in symfony/security-bundle","details":"symfony/security-bundle is a module for the Symphony PHP framework which provides a tight integration of the Security component into the Symfony full-stack framework. The custom `user_checker` defined on a firewall is not called when Login Programmaticaly with the `Security::login` method, leading to  unwanted login. As of versions 6.4.10, 7.0.10 and 7.1.3 the `Security::login` method now ensure to call the configured `user_checker`. All users are advised to upgrade. There are no known workarounds for this vulnerability.","aliases":["GHSA-jxgr-3v7q-3w9v"],"modified":"2026-08-11T03:30:08.292661321Z","published":"2024-11-06T21:06:49.426Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/50xxx/CVE-2024-50341.json","cna_assigner":"GitHub_M","cwe_ids":["CWE-287"]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/50xxx/CVE-2024-50341.json"},{"type":"ADVISORY","url":"https://github.com/symfony/symfony/security/advisories/GHSA-jxgr-3v7q-3w9v"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-50341"},{"type":"FIX","url":"https://github.com/symfony/symfony/commit/22a0789a0085c3ee96f4ef715ecad8255cf0e105"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/symfony/symfony","events":[{"introduced":"ed9b9e7795c3e30c6d70c6ecf013a28910f6e15e"},{"introduced":"d78c5f403d7ee794993660b1d5155536edd36fc1"},{"introduced":"08964d6da4787cd5f19e60f8aaf41ffd26d6c8c3"},{"fixed":"938c0728518f9df199477d90ee43838359f81a7a"},{"fixed":"96e43bf86ac6126cc61a634b34987821b69f7af9"},{"fixed":"60ccc390f438c3a11b601d385b77c6f2431ffc5d"},{"fixed":"22a0789a0085c3ee96f4ef715ecad8255cf0e105"}],"database_specific":{"source":["AFFECTED_FIELD","REFERENCES"],"extracted_events":[{"introduced":"6.2.0"},{"fixed":"6.4.10"},{"introduced":"7.0.0"},{"fixed":"7.0.10"},{"introduced":"7.1.0"},{"fixed":"7.1.3"}]}}],"versions":["v7.1.2","v7.0.9","v7.1.1","v7.0.8","v7.1.0","v7.0.7","v7.0.6","v7.0.5","v7.0.4","v7.0.3","v7.0.2","v7.0.1","v7.0.0"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-50341.json"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N"}]}