GHSA-m2wj-r6g3-fxfx

    Dashboard / Vulnerabilities / GHSA-m2wj-r6g3-fxfx

    GHSA-m2wj-r6g3-fxfx

    Published: 12 Nov 2023Last Modified: 10 Sept 2026

    Summary: Symfony possible session fixation vulnerability

    Details: ### Description SessionStrategyListener does not always migrate the session after a successful login. It only migrate the session when the logged-in user identifier changes. In some use cases, the user identifier doesn't change between the verification phase and the successful login, while the token itself changes from one type (partially-authenticated) to another (fully-authenticated). When this happens, the session id should be regenerated to prevent possible session fixations. ### Resolution Symfony now checks the type of the token in addition to the user identifier before deciding whether the session id should be regenerated. The patch for this issue is available [here](https://github.com/symfony/symfony/commit/dc356499d5ceb86f7cf2b4c7f032eca97061ed74) for branch 5.4. ### Credits We would like to thank Robert Meijers for reporting the issue and providing the fix.

    Affected packages

    Package

    Name: symfony/security-http

    Purl: pkg:composer/symfony/security-http

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 5.4.21
    Fixed -5.4.31

    Affected versions

    v5.4.21
    v5.4.22
    v5.4.23
    v5.4.26
    v5.4.28
    v5.4.30

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-m2wj-r6g3-fxfx | CVE-DB