symfony/security-http is vulnerable to Authentication Bypass by Spoofing
75
High Risk
X509Authenticator extracts the user identifier from a client certificate subject DN using an unanchored match. A certificate subject can place an emailAddress fragment inside another RDN value and be interpreted as a different identity. Pre-fix mTLS authentication can accept a certificate as the wrong user when the CA permits such subject values. The fix anchors extraction to RDN boundaries.
You are affected if you are using a version that falls within the vulnerable range.
symfony/security-http is vulnerable to Authentication Bypass by Spoofing in versions 0.0.1 - 5.4.51, 6.0.0 - 6.4.39, 7.0.0 - 7.4.11 and 8.0.0 - 8.0.11.
Upgrade the symfony/security-http and/or symfony/symfony library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant