Denial of Service Vulnerability in FriendsOfSymfony FOSUserBundle

Denial of Service Vulnerability in FriendsOfSymfony FOSUserBundle

CVE-2013-5750 · MEDIUM Severity

AV:N/AC:L/AU:N/C:N/I:N/A:P

The login form in the FriendsOfSymfony FOSUserBundle bundle before 1.3.3 for Symfony allows remote attackers to cause a denial of service (CPU consumption) via a long password that triggers an expensive hash computation, as demonstrated by a PBKDF2 computation.

Learn more about our Cis Benchmark Audit For Suse Linux Enterprise Server.