Security Advisory

CVE-2016-2403

9.8
CRITICAL

Vulnerability Description

Symfony before 2.8.6 and 3.x before 3.0.6 allows remote attackers to bypass authentication by logging in with an empty password and valid username, which triggers an unauthenticated bind.
Published Date February 7, 2017
Official Source NIST NVD Advisory