GHSA-qw36-p97w-vcqr · Severity: medium · Ecosystem: composer — Cookie persistence after password changes in symfony/security-bundle
Symfony/SecurityBundle is the security system for Symfony, a PHP framework for web and console applications and a set of reusable PHP components. Since the rework of the Remember me cookie in version 5.3.0, the cookie is not invalidated when the user changes their password. Attackers can therefore maintain their access to the account even if the password is changed as long as they have had the chance to login once and get a valid remember me cookie. Starting with version 5.3.12, Symfony makes the password part of the signature by default. In that way, when the password changes, then the cookie is not valid anymore.
Conclusion & alert: CVE-2021-41268 is rated Moderate Risk (48.5/100): CVSS Medium severity, with medium exploitation likelihood (EPSS 0.48%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2025-11-21 | 0.41% | 0.48% | +0.07% |
| 2 | 2025-11-18 | 0.45% | 0.41% | -0.04% |
| 3 | 2025-03-30 | — | 0.45% | — |
Full EPSS history (10 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 6.5 | 3.1 | MEDIUM |
|
2.8 | 3.6 | [email protected] |
| 8.8 | 3.1 | HIGH |
|
2.8 | 5.9 | [email protected] |
| 6.5 | 2.0 | MEDIUM |
|
8.0 | 6.4 | [email protected] |
GHSA-qw36-p97w-vcqr · Severity: medium · Ecosystem: composer — Cookie persistence after password changes in symfony/security-bundle
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
unimportant | CVE-2021-41268 unimportant priority: Debian including 1 source packages (symfony), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. | https://security-tracker.debian.org/tracker/CVE-2021-41268 |
ubuntu
|
medium | CVE-2021-41268 medium priority: Ubuntu including 1 source packages (symfony), 8 status rows across 8 suites (bionic, focal, hirsute, impish, jammy, trusty, upstream, xenial): not-affected 6, ignored 2. | https://ubuntu.com/security/CVE-2021-41268 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| sensiolabs | symfony | >= 5.3.0, < 5.3.12 | cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://github.com/symfony/symfony/commit/36a808b857cd3240244f4b224452fb1e70dc6dfc | Patch Third Party Advisory |
| https://github.com/symfony/symfony/pull/44243 | Patch Third Party Advisory |
| https://github.com/symfony/symfony/releases/tag/v5.3.12 | Release Notes Third Party Advisory |
| https://github.com/symfony/symfony/security/advisories/GHSA-qw36-p97w-vcqr | Patch Third Party Advisory |