{"id":"GHSA-m2wj-r6g3-fxfx","summary":"Symfony possible session fixation vulnerability","details":"### Description\n\nSessionStrategyListener does not always migrate the session after a successful login. It only migrate the session when the logged-in user identifier changes. In some use cases, the user identifier doesn't change between the verification phase and the successful login, while the token itself changes from one type (partially-authenticated) to another (fully-authenticated). When this happens, the session id should be regenerated to prevent possible session fixations.\n\n### Resolution\n\nSymfony now checks the type of the token in addition to the user identifier before deciding whether the session id should be regenerated.\n\nThe patch for this issue is available [here](https://github.com/symfony/symfony/commit/dc356499d5ceb86f7cf2b4c7f032eca97061ed74) for branch 5.4.\n\n### Credits\n\nWe would like to thank Robert Meijers for reporting the issue and providing the fix.","aliases":["BIT-symfony-2023-46733","CVE-2023-46733"],"modified":"2026-09-10T03:50:04.290059815Z","published":"2023-11-12T15:51:54Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2023-11-12T15:51:54Z","nvd_published_at":"2023-11-10T18:15:09Z","cwe_ids":["CWE-384"]},"references":[{"type":"WEB","url":"https://github.com/symfony/symfony/security/advisories/GHSA-m2wj-r6g3-fxfx"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-46733"},{"type":"WEB","url":"https://github.com/symfony/symfony/commit/7467bd7e3f888b333102bc664b5e02ef1e7f88b9"},{"type":"WEB","url":"https://github.com/symfony/symfony/commit/dc356499d5ceb86f7cf2b4c7f032eca97061ed74"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/symfony/CVE-2023-46733.yaml"},{"type":"PACKAGE","url":"https://github.com/symfony/symfony"},{"type":"WEB","url":"https://symfony.com/cve-2023-46733"}],"affected":[{"package":{"name":"symfony/security-http","ecosystem":"Packagist","purl":"pkg:composer/symfony/security-http"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.4.21"},{"fixed":"5.4.31"}]}],"versions":["v5.4.21","v5.4.22","v5.4.23","v5.4.26","v5.4.28","v5.4.30"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/11/GHSA-m2wj-r6g3-fxfx/GHSA-m2wj-r6g3-fxfx.json"}},{"package":{"name":"symfony/security-http","ecosystem":"Packagist","purl":"pkg:composer/symfony/security-http"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"6.2.7"},{"fixed":"6.3.8"}]}],"versions":["v6.2.10","v6.2.11","v6.2.13","v6.2.7","v6.2.8","v6.3.0","v6.3.0-BETA1","v6.3.0-RC1","v6.3.1","v6.3.2","v6.3.4","v6.3.5","v6.3.6"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/11/GHSA-m2wj-r6g3-fxfx/GHSA-m2wj-r6g3-fxfx.json"}},{"package":{"name":"symfony/symfony","ecosystem":"Packagist","purl":"pkg:composer/symfony/symfony"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.4.21"},{"fixed":"5.4.31"}]}],"versions":["v5.4.21","v5.4.22","v5.4.23","v5.4.24","v5.4.25","v5.4.26","v5.4.27","v5.4.28","v5.4.29","v5.4.30"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/11/GHSA-m2wj-r6g3-fxfx/GHSA-m2wj-r6g3-fxfx.json"}},{"package":{"name":"symfony/symfony","ecosystem":"Packagist","purl":"pkg:composer/symfony/symfony"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"6.2.7"},{"fixed":"6.3.8"}]}],"versions":["v6.2.10","v6.2.11","v6.2.12","v6.2.13","v6.2.14","v6.2.7","v6.2.8","v6.2.9","v6.3.0","v6.3.0-BETA1","v6.3.0-BETA2","v6.3.0-BETA3","v6.3.0-RC1","v6.3.0-RC2","v6.3.1","v6.3.2","v6.3.3","v6.3.4","v6.3.5","v6.3.6","v6.3.7"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/11/GHSA-m2wj-r6g3-fxfx/GHSA-m2wj-r6g3-fxfx.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"}]}