CVE-2024-50342

CVSS 3.1 Score 3.1 of 10 (low)

Details

Published Nov 6, 2024
CWE ID 200

Summary

CVE-2024-50342 affects the symfony/http-client module in the Symphony PHP framework, which is used for fetching HTTP resources synchronously or asynchronously. This vulnerability allows for possible IP/port enumeration during host resolution with the `NoPrivateNetworkHttpClient`. Affected versions include 5.4.45, 6.4.13, and 7.1.6. To prevent the leaking of internal information, affected users are advised to upgrade to the latest versions (5.4.46, 6.4.14, and 7.1.7), as there are currently no known workarounds for this issue.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share