Executive brief
FOSUserBundle is a library used by Symfony-based websites to manage user accounts and authentication. A security flaw was identified where the system incorrectly validated user identities when refreshing a session. If a user was allowed to change their username, this flaw could potentially lead to unauthorized access or identity confusion within the application.
Technical details
The vulnerability is classified as Improper Authorization (CWE-285) within the user refreshing logic of FOSUserBundle. In affected versions, the bundle refreshed user sessions using the database primary key rather than the username. This creates a synchronization risk in scenarios where a user is permitted to change their username, potentially allowing a session to persist or be associated with incorrect identity data. The issue was resolved in version 1.2.1 by ensuring the user is loaded using the primary key correctly during the refreshing process to maintain identity integrity.
Affected products
- friendsofsymfony user-bundle >= 1.0.0, < 1.2.1
Timeline
- 2024-05-15: advisory: GitHub Advisory published
- 2012-07-10: patched: Date referenced in security advisory YAML for version 1.2.1 fix