VYPR
Low severityNVD Advisory· Published Dec 7, 2015· Updated May 6, 2026

CVE-2015-8124

CVE-2015-8124

Description

Session fixation vulnerability in the "Remember Me" login feature in Symfony 2.3.x before 2.3.35, 2.6.x before 2.6.12, and 2.7.x before 2.7.7 allows remote attackers to hijack web sessions via a session id.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
symfony/symfonyPackagist
>= 2.3.0, < 2.3.352.3.35
symfony/symfonyPackagist
>= 2.4.0, < 2.6.122.6.12
symfony/symfonyPackagist
>= 2.7.0, < 2.7.72.7.7
symfony/security-httpPackagist
>= 2.4.0, < 2.6.122.6.12
symfony/security-httpPackagist
>= 2.7.0, < 2.7.72.7.7
symfony/securityPackagist
>= 2.3.0, < 2.3.352.3.35
symfony/securityPackagist
>= 2.4.0, < 2.6.122.6.12
symfony/securityPackagist
>= 2.7.0, < 2.7.72.7.7

Affected products

54
  • Sensiolabs/Symfony54 versions
    cpe:2.3:a:sensiolabs:symfony:2.3.0:*:*:*:*:*:*:*+ 53 more
    • cpe:2.3:a:sensiolabs:symfony:2.3.0:*:*:*:*:*:*:*
    • cpe:2.3:a:sensiolabs:symfony:2.3.1:*:*:*:*:*:*:*
    • cpe:2.3:a:sensiolabs:symfony:2.3.10:*:*:*:*:*:*:*
    • cpe:2.3:a:sensiolabs:symfony:2.3.11:*:*:*:*:*:*:*
    • cpe:2.3:a:sensiolabs:symfony:2.3.12:*:*:*:*:*:*:*
    • cpe:2.3:a:sensiolabs:symfony:2.3.13:*:*:*:*:*:*:*
    • cpe:2.3:a:sensiolabs:symfony:2.3.14:*:*:*:*:*:*:*
    • cpe:2.3:a:sensiolabs:symfony:2.3.15:*:*:*:*:*:*:*
    • cpe:2.3:a:sensiolabs:symfony:2.3.16:*:*:*:*:*:*:*
    • cpe:2.3:a:sensiolabs:symfony:2.3.17:*:*:*:*:*:*:*
    • cpe:2.3:a:sensiolabs:symfony:2.3.18:*:*:*:*:*:*:*
    • cpe:2.3:a:sensiolabs:symfony:2.3.19:*:*:*:*:*:*:*
    • cpe:2.3:a:sensiolabs:symfony:2.3.2:*:*:*:*:*:*:*
    • cpe:2.3:a:sensiolabs:symfony:2.3.20:*:*:*:*:*:*:*
    • cpe:2.3:a:sensiolabs:symfony:2.3.21:*:*:*:*:*:*:*
    • cpe:2.3:a:sensiolabs:symfony:2.3.22:*:*:*:*:*:*:*
    • cpe:2.3:a:sensiolabs:symfony:2.3.23:*:*:*:*:*:*:*
    • cpe:2.3:a:sensiolabs:symfony:2.3.24:*:*:*:*:*:*:*
    • cpe:2.3:a:sensiolabs:symfony:2.3.25:*:*:*:*:*:*:*
    • cpe:2.3:a:sensiolabs:symfony:2.3.26:*:*:*:*:*:*:*
    • cpe:2.3:a:sensiolabs:symfony:2.3.27:*:*:*:*:*:*:*
    • cpe:2.3:a:sensiolabs:symfony:2.3.28:*:*:*:*:*:*:*
    • cpe:2.3:a:sensiolabs:symfony:2.3.29:*:*:*:*:*:*:*
    • cpe:2.3:a:sensiolabs:symfony:2.3.3:*:*:*:*:*:*:*
    • cpe:2.3:a:sensiolabs:symfony:2.3.30:*:*:*:*:*:*:*
    • cpe:2.3:a:sensiolabs:symfony:2.3.31:*:*:*:*:*:*:*
    • cpe:2.3:a:sensiolabs:symfony:2.3.32:*:*:*:*:*:*:*
    • cpe:2.3:a:sensiolabs:symfony:2.3.33:*:*:*:*:*:*:*
    • cpe:2.3:a:sensiolabs:symfony:2.3.34:*:*:*:*:*:*:*
    • cpe:2.3:a:sensiolabs:symfony:2.3.4:*:*:*:*:*:*:*
    • cpe:2.3:a:sensiolabs:symfony:2.3.5:*:*:*:*:*:*:*
    • cpe:2.3:a:sensiolabs:symfony:2.3.6:*:*:*:*:*:*:*
    • cpe:2.3:a:sensiolabs:symfony:2.3.7:*:*:*:*:*:*:*
    • cpe:2.3:a:sensiolabs:symfony:2.3.8:*:*:*:*:*:*:*
    • cpe:2.3:a:sensiolabs:symfony:2.3.9:*:*:*:*:*:*:*
    • cpe:2.3:a:sensiolabs:symfony:2.6.0:*:*:*:*:*:*:*
    • cpe:2.3:a:sensiolabs:symfony:2.6.1:*:*:*:*:*:*:*
    • cpe:2.3:a:sensiolabs:symfony:2.6.10:*:*:*:*:*:*:*
    • cpe:2.3:a:sensiolabs:symfony:2.6.11:*:*:*:*:*:*:*
    • cpe:2.3:a:sensiolabs:symfony:2.6.2:*:*:*:*:*:*:*
    • cpe:2.3:a:sensiolabs:symfony:2.6.3:*:*:*:*:*:*:*
    • cpe:2.3:a:sensiolabs:symfony:2.6.4:*:*:*:*:*:*:*
    • cpe:2.3:a:sensiolabs:symfony:2.6.5:*:*:*:*:*:*:*
    • cpe:2.3:a:sensiolabs:symfony:2.6.6:*:*:*:*:*:*:*
    • cpe:2.3:a:sensiolabs:symfony:2.6.7:*:*:*:*:*:*:*
    • cpe:2.3:a:sensiolabs:symfony:2.6.8:*:*:*:*:*:*:*
    • cpe:2.3:a:sensiolabs:symfony:2.6.9:*:*:*:*:*:*:*
    • cpe:2.3:a:sensiolabs:symfony:2.7.0:*:*:*:*:*:*:*
    • cpe:2.3:a:sensiolabs:symfony:2.7.1:*:*:*:*:*:*:*
    • cpe:2.3:a:sensiolabs:symfony:2.7.2:*:*:*:*:*:*:*
    • cpe:2.3:a:sensiolabs:symfony:2.7.3:*:*:*:*:*:*:*
    • cpe:2.3:a:sensiolabs:symfony:2.7.4:*:*:*:*:*:*:*
    • cpe:2.3:a:sensiolabs:symfony:2.7.5:*:*:*:*:*:*:*
    • cpe:2.3:a:sensiolabs:symfony:2.7.6:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

16

News mentions

0

No linked articles in our index yet.