CVE-2023-46733

    Dashboard / Vulnerabilities / CVE-2023-46733

    CVE-2023-46733

    Published: 10 Nov 2023Last Modified: 12 Aug 2026

    Summary: Symfony possible session fixation vulnerability

    Details: Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Starting in versions 5.4.21 and 6.2.7 and prior to versions 5.4.31 and 6.3.8, `SessionStrategyListener` does not migrate the session after every successful login. It does so only in case the logged in user changes by means of checking the user identifier. In some use cases, the user identifier doesn't change between the verification phase and the successful login, while the token itself changes from one type (partially-authenticated) to another (fully-authenticated). When this happens, the session id should be regenerated to prevent possible session fixations, which is not the case at the moment. As of versions 5.4.31 and 6.3.8, Symfony now checks the type of the token in addition to the user identifier before deciding whether the session id should be regenerated.

    Affected packages

    Package

    Name:

    Purl:

    Affected ranges

    Type: GIT

    Events:

    Introduced- 0570380d0864d3fa5f8c07b59ada16149bf0570a

    Affected versions

    v5.4.30
    v5.4.28
    v5.4.26
    v5.4.23
    v5.4.22
    v5.4.21
    v5.4.29
    v5.4.27
    v5.4.25
    v5.4.24

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    CVE-2023-46733 | CVE-DB