Symfony before 2.8.6 and 3.x before 3.0.6 allows remote attackers to bypass authentication by logging in with an empty password and valid username, which triggers an unauthenticated bind.
https://github.com/advisories/GHSA-wvj5-r78r-hhfq
https://www.debian.org/security/2018/dsa-4262