ended4월 4일· 1 sources

Auth0 Symfony Users at Risk: Session Hijacking via Weak Cookie Encryption Flaw

Auth0 Symfony SDK 암호화 결함으로 세션 탈취 가능, 긴급 업그레이드 필요

Why it matters

This vulnerability exposes a critical flaw in Auth0 Symfony SDK's cookie encryption that allows attackers to forge authentication sessions and take over user accounts without passwords. Organizations using affected versions (5.0.0-5.7.0) must immediately upgrade to version 5.8.0 or higher and rotate session encryption keys to prevent ongoing exploitation and invalidate potentially compromised sessions.

1
Sources
+0
24h
Growth
170d
Active
Auth0 SymfonyCookie encryptionSession forgeryAccount takeoverInsufficient entropy

Sources

Related Issues