Intel

AIKIDO-2024-10124

symfony/password-hasher is vulnerable to Information Disclosure

Information Disclosure Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Jun 7, 2024

20

Low Risk

This Affects:

phpsymfony/password-hasher
5.3.0 - 6.1.11
Fixed in 6.2.0
7.0.0 - 7.0.8
Fixed in 7.1.0
Are you affected? Scan for Free

TL;DR

Affected versions of symfony/password-hasher are vulnerable to potential information disclosure of passwords in backtraces, which may be sent to error logging and monitoring tools like Sentry.

Who does this affect?

You are affected if you use a vulnerable version of symfony/password-hasher.

Background info

symfony/password-hasher is vulnerable to Information Disclosure in versions 5.3.0 - 6.1.11 and 7.0.0 - 7.0.8.

How to fix this

Upgrade symfony/password-hasher to a patch version (6.2.0 or 7.1.0).