CVE-2024-50340

CVSS 3.1 Score 7.3 of 10 (high)

Details

Published Nov 6, 2024
Updated: Nov 8, 2024
CWE ID 74

Summary

CVE-2024-50340 is a vulnerability affecting the Symfony/runtime module of the Symfony PHP framework. This module allows decoupling PHP applications from global state. When the `register_argv_argc` PHP directive is set to `on`, attackers can manipulate query strings to change the environment or debug mode used by the kernel during request handling. This issue affects Symfony versions 5.4.46, 6.4.14, and 7.1.7. The latest versions of Symfony now ignore `argv` values for non-SAPI PHP runtimes, making an upgrade essential to mitigate this vulnerability. No known workarounds are available.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share