CVE-2024-50342
CVSS 3.1 Score 3.1 of 10 (low)
Details
Published Nov 6, 2024
CWE ID 200
Summary
CVE-2024-50342 affects the symfony/http-client module in the Symphony PHP framework, which is used for fetching HTTP resources synchronously or asynchronously. This vulnerability allows for possible IP/port enumeration during host resolution with the `NoPrivateNetworkHttpClient`. Affected versions include 5.4.45, 6.4.13, and 7.1.6. To prevent the leaking of internal information, affected users are advised to upgrade to the latest versions (5.4.46, 6.4.14, and 7.1.7), as there are currently no known workarounds for this issue.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share