CVE-2018-11385: Debian Linux
High severity, CVSS 8.1. EPSS: 2% chance of exploitation in the next 30 days.
An issue was discovered in the Security component in Symfony 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x before 4.0.11. A session fixation vulnerability within the "Guard" login feature may allow an attacker to impersonate a victim towards the web application if the session id value was previously known to the attacker.
Affected products
- Debian Debian Linux: version 8.0 only; version 9.0 only
- Fedoraproject Fedora: version 28 only
- Sensiolabs Symfony: from 2.7.0, before 2.7.48 (fixed in 2.7.48); from 2.8.0, before 2.8.41 (fixed in 2.8.41); from 3.3.0, before 3.3.17 (fixed in 3.3.17); from 3.4.0, before 3.4.11 (fixed in 3.4.11); from 4.0.0, before 4.0.11 (fixed in 4.0.11)
Published 2018-06-13. Last modified 2026-06-17.