CVE-2024-50341: Symfony

Low severity, CVSS 3.1. EPSS: 0.3% chance of exploitation in the next 30 days.

symfony/security-bundle is a module for the Symphony PHP framework which provides a tight integration of the Security component into the Symfony full-stack framework. The custom `user_checker` defined on a firewall is not called when Login Programmaticaly with the `Security::login` method, leading to unwanted login. As of versions 6.4.10, 7.0.10 and 7.1.3 the `Security::login` method now ensure to call the configured `user_checker`. All users are advised to upgrade. There are no known workarounds for this vulnerability.

Affected products

  • Symfony Symfony: from 6.2.0, before 6.4.10 (fixed in 6.4.10); from 7.0.0, before 7.0.10 (fixed in 7.0.10); from 7.1.0, before 7.1.3 (fixed in 7.1.3)

Published 2024-11-06. Last modified 2026-06-17.