{"id":"GHSA-9mpf-g3fc-9rgv","summary":"FriendsOfSymfony FOSUserBundle denial of service via login form","details":"The login form in the FriendsOfSymfony FOSUserBundle bundle before 1.3.3 for Symfony allows remote attackers to cause a denial of service (CPU consumption) via a long password that triggers an expensive hash computation, as demonstrated by a PBKDF2 computation.","aliases":["CVE-2013-5750"],"modified":"2024-12-06T05:33:16.697212Z","published":"2022-05-17T05:00:37Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2024-04-23T22:47:11Z","nvd_published_at":"2013-09-25T10:31:00Z","cwe_ids":["CWE-400"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2013-5750"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/friendsofsymfony/user-bundle/CVE-2013-5750.yaml"},{"type":"WEB","url":"https://symfony.com/cve-2013-5750"},{"type":"WEB","url":"http://symfony.com/blog/cve-2013-5750-security-issue-in-fosuserbundle-login-form"}],"affected":[{"package":{"name":"friendsofsymfony/user-bundle","ecosystem":"Packagist","purl":"pkg:composer/friendsofsymfony/user-bundle"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.2.0"},{"fixed":"1.2.5"}]}],"versions":["1.2.0","v1.2.1","v1.2.2","v1.2.3","v1.2.4"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-9mpf-g3fc-9rgv/GHSA-9mpf-g3fc-9rgv.json"}},{"package":{"name":"friendsofsymfony/user-bundle","ecosystem":"Packagist","purl":"pkg:composer/friendsofsymfony/user-bundle"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.3.0"},{"fixed":"1.3.3"}]}],"versions":["v1.3.0","v1.3.1","v1.3.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-9mpf-g3fc-9rgv/GHSA-9mpf-g3fc-9rgv.json"}}],"schema_version":"1.9.0"}