CVE-2013-5750: Friends Of Symfony Project Fosuserbundle

Medium severity, CVSS 5.0. EPSS: 1.2% chance of exploitation in the next 30 days.

The login form in the FriendsOfSymfony FOSUserBundle bundle before 1.3.3 for Symfony allows remote attackers to cause a denial of service (CPU consumption) via a long password that triggers an expensive hash computation, as demonstrated by a PBKDF2 computation.

Affected products

  • Friends Of Symfony Project Fosuserbundle: up to and including 1.3.2; version 1.0.0 only; version 1.1.0 only; version 1.2.0 only; version 1.2.1 only; version 1.2.3 only; …

Published 2013-09-25. Last modified 2026-06-16.