CVE-2017-11365: Sensiolabs Symfony

Critical severity, CVSS 9.8. EPSS: 1.9% chance of exploitation in the next 30 days.

Certain Symfony products are affected by: Incorrect Access Control. This affects Symfony 2.7.30 and Symfony 2.8.23 and Symfony 3.2.10 and Symfony 3.3.3. The type of exploitation is: remote. The component is: Password validator.

Affected products

  • Sensiolabs Symfony: version 2.7.30 only; version 2.8.23 only; version 3.2.10 only; version 3.3.3 only

Published 2019-05-23. Last modified 2026-06-17.