PT-2024-34155 · Symfony+5 · Symfony Httpfoundation+5
Zer0Yu
·
Published
2024-10-29
·
Updated
2025-07-01
·
CVE-2024-50345
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
symfony/http-foundation versions prior to 5.4.46
symfony/http-foundation versions prior to 6.4.14
symfony/http-foundation versions prior to 7.1.7
Description:
The
Request class in symfony/http-foundation does not parse URI with special characters the same way browsers do. As a result, an attacker can trick a validator relying on the Request class to redirect users to another domain. The issue has been patched, and users are advised to upgrade. There are no known workarounds for this issue.Recommendations:
For versions prior to 5.4.46, upgrade to version 5.4.46 or later.
For versions prior to 6.4.14, upgrade to version 6.4.14 or later.
For versions prior to 7.1.7, upgrade to version 7.1.7 or later.
As a temporary workaround, consider validating URLs manually to ensure they do not contain invalid characters as defined by https://url.spec.whatwg.org/ until a patch is applied.
Exploit
Fix
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Astra Linux
Debian
Linuxmint
Red Os
Ubuntu
Symfony Httpfoundation