GHSA-8wx3-8m4x-g5h4MediumDisclosed before NVD

FOSUserBundle User Identity Validation Vulnerability

Published
May 15, 2024
Last Modified
July 16, 2026

📋 Description

Versions of FOSUserBundle prior to 1.2.1 have been found to be vulnerable to a security issue related to user identity validation. Specifically, user refreshing was performed using the primary key instead of the username, leading to a potential security risk if a user is allowed to change their username. The fix in version 1.2.1 addresses this issue by loading the user using the primary key during refreshing.

🎯 Affected products1

  • composer/friendsofsymfony/user-bundle:>= 1.0.0, < 1.2.1

🔗 References (5)