{"id":"CVE-2018-11407","details":"An issue was discovered in the Ldap component in Symfony 2.8.x before 2.8.37, 3.3.x before 3.3.17, 3.4.x before 3.4.7, and 4.0.x before 4.0.7. It allows remote attackers to bypass authentication by logging in with a \"null\" password and valid username, which triggers an unauthenticated bind.  NOTE: this issue exists because of an incomplete fix for CVE-2016-2403.","aliases":["GHSA-35c5-28pg-2qg4"],"modified":"2026-08-07T15:11:21.750854Z","published":"2018-06-13T16:29:01.047Z","references":[{"type":"ADVISORY","url":"https://symfony.com/blog/cve-2018-11407-unauthorized-access-on-a-misconfigured-ldap-server-when-using-an-empty-password"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/symfony/security-http","events":[{"introduced":"a8d5dd00894f8b5e3edb897f4504c51ddc442370"},{"fixed":"779963cae79262cc38d7bb2ad7f15f21ee80a16d"},{"introduced":"760872233cd3147870184697e3481ffa492ac2fb"},{"fixed":"7cb076f64ed0310504caaad1180a211be949c5db"},{"introduced":"33c98765dc6fec4907b7431d10e3c0945f061108"},{"fixed":"a89f25cb4a379d200f2029e714dd6107acfa944d"},{"introduced":"afa69c531f22fb4b9fc95017ec0e5d6c77db0c3c"},{"fixed":"db68b498bbc6f98b400ee0657c2dbbc48f321d4f"}],"database_specific":{"cpe":"cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"2.8.0"},{"fixed":"2.8.37"},{"introduced":"3.3.0"},{"fixed":"3.3.17"},{"introduced":"3.4.0"},{"fixed":"3.4.7"},{"introduced":"4.0.0"},{"fixed":"4.0.7"}],"source":"CPE_RANGE"}}],"versions":["v3.3.16","v4.0.4","v3.4.4","v2.8.34","v4.0.3","v3.4.3","v3.3.15","v2.8.33","v4.0.2","v4.0.1","v4.0.0-RC2","v4.0.0","v3.4.2","v3.4.1","v3.4.0-RC2","v3.4.0-RC1","v3.4.0","v3.3.14","v3.3.13","v2.8.32","v2.8.31","v3.3.12","v3.3.11","v2.8.30","v2.8.29","v3.3.10","v2.8.28","v3.3.9","v3.3.8","v3.3.7","v2.8.27","v2.8.26","v3.3.6","v3.3.5","v3.3.4","v3.3.3","v2.8.25","v2.8.24","v2.8.23","v3.3.2","v3.3.1","v3.3.0","v2.8.22","v2.8.21","v2.8.20","v2.8.19","v2.8.18","v2.8.17","v2.8.16","v2.8.15","v2.8.14","v2.8.13","v2.8.12","v2.8.11","v2.8.10","v2.8.9","v2.8.8","v2.8.7","v2.8.6","v2.8.5","v2.8.4","v2.8.3","v2.8.2","v2.8.1","v2.8.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-11407.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/symfony/symfony","events":[{"introduced":"5615b92cd452cd54f1433a3f53de87c096a1107f"},{"fixed":"e5150a094b08887356b2b90805538836208d4569"},{"introduced":"5a7e31c48e7cd4831efa409fffb661beb9995174"},{"fixed":"4639525c796227ec36652ad97192a5eb3de74f76"},{"introduced":"0a47db379b8cc74cdd84e1e6870fafc4a4ac8351"},{"fixed":"eb07b0eab0bda8441fbf94d06ad1f9896e0552cc"},{"introduced":"26ca7023b1c45dce951da7206ed70049267d27bc"},{"fixed":"42ef10b276fc748468c40cef417253a08c46728f"}],"database_specific":{"cpe":"cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"2.8.0"},{"fixed":"2.8.37"},{"introduced":"3.3.0"},{"fixed":"3.3.17"},{"introduced":"3.4.0"},{"fixed":"3.4.7"},{"introduced":"4.0.0"},{"fixed":"4.0.7"}],"source":"CPE_RANGE"}}],"versions":["v4.0.6","v3.4.6","v2.8.36","v4.0.5","v3.4.5","v2.8.35","v4.0.4","v3.4.4","v3.3.16","v2.8.34","v4.0.3","v3.4.3","v3.3.15","v2.8.33","v4.0.2","v3.4.2","v4.0.1","v3.4.1","v3.3.14","v2.8.32","v4.0.0","v3.4.0","v3.3.13","v2.8.31","v3.3.12","v2.8.30","v3.3.11","v2.8.29","v3.3.10","v2.8.28","v3.3.9","v3.3.8","v3.3.7","v2.8.27","v3.3.6","v2.8.26","v3.3.5","v2.8.25","v3.3.4","v2.8.24","v3.3.3","v2.8.23","v2.8.22","v3.3.2","v3.3.1","v3.3.0","v2.8.21","v2.8.20","v2.8.18","v2.8.19","v2.8.17","v2.8.16","v2.8.15","v2.8.14","v2.8.13","v2.8.12","v2.8.11","v2.8.10","v2.8.9","v2.8.8","v2.8.7","v2.8.6","v2.8.5","v2.8.4","v2.8.3","v2.8.2","v2.8.1","v2.8.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-11407.json"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}