CVE-2024-50340
CVSS 3.1 Score 7.3 of 10 (high)
Details
Summary
CVE-2024-50340 is a vulnerability affecting the Symfony/runtime module of the Symfony PHP framework. This module allows decoupling PHP applications from global state. When the `register_argv_argc` PHP directive is set to `on`, attackers can manipulate query strings to change the environment or debug mode used by the kernel during request handling. This issue affects Symfony versions 5.4.46, 6.4.14, and 7.1.7. The latest versions of Symfony now ignore `argv` values for non-SAPI PHP runtimes, making an upgrade essential to mitigate this vulnerability. No known workarounds are available.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.