{"id":"GHSA-8wx3-8m4x-g5h4","summary":"FOSUserBundle User Identity Validation Vulnerability","details":"Versions of FOSUserBundle prior to 1.2.1 have been found to be vulnerable to a security issue related to user identity validation. Specifically, user refreshing was performed using the primary key instead of the username, leading to a potential security risk if a user is allowed to change their username. The fix in version 1.2.1 addresses this issue by loading the user using the primary key during refreshing.","modified":"2026-07-16T18:45:58.900118812Z","published":"2024-05-15T21:43:23Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2024-05-15T21:43:23Z","nvd_published_at":null,"cwe_ids":["CWE-285"]},"references":[{"type":"WEB","url":"https://github.com/FriendsOfSymfony/FOSUserBundle/commit/1b8bc18e3d99ef0b52b4141f20da323033d6be9b"},{"type":"WEB","url":"https://github.com/FriendsOfSymfony/FOSUserBundle/commit/5a36e2958068d1e6501dc8cf39bbae3ebb859d9f"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/friendsofsymfony/user-bundle/2012-07-10-1.yaml"},{"type":"PACKAGE","url":"https://github.com/FriendsOfSymfony/FOSUserBundle"},{"type":"WEB","url":"https://github.com/FriendsOfSymfony/FOSUserBundle/blob/master/Changelog.md"}],"affected":[{"package":{"name":"friendsofsymfony/user-bundle","ecosystem":"Packagist","purl":"pkg:composer/friendsofsymfony/user-bundle"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.0.0"},{"fixed":"1.2.1"}]}],"versions":["1.1.0","1.2.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/05/GHSA-8wx3-8m4x-g5h4/GHSA-8wx3-8m4x-g5h4.json"}}],"schema_version":"1.9.0"}