PT-2024-7999 · Symfony+5 · Symfony+5

Vladimir Dusheyko

·

Published

2023-10-07

·

Updated

2025-07-01

·

CVE-2024-50340

CVSS v3.1

7.3

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Symfony versions prior to 5.4.46 Symfony versions prior to 6.4.14 Symfony versions prior to 7.1.7
Description The issue exists due to the lack of measures to neutralize special elements, allowing a remote attacker to execute arbitrary code. When the register argv argc php directive is set to on, and users call any URL with a specially crafted query string, they are able to change the environment or debug mode used by the kernel when handling the request. Over 32,000 results are found to be potentially vulnerable.
Recommendations For versions prior to 5.4.46, update to version 5.4.46 or later. For versions prior to 6.4.14, update to version 6.4.14 or later. For versions prior to 7.1.7, update to version 7.1.7 or later. As a temporary workaround, consider setting the register argv argc php directive to off until a patch is applied.

Exploit

Fix

DoS

Information Disclosure

Open Redirect

RCE

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2023-6184
ALT-PU-2024-1028
ALT-PU-2024-4537
ALT-PU-2024-4547
ALT-PU-2024-4961
ALT-PU-2025-4212
BDU:2024-09513
BDU:2025-07863
BDU:2025-07864
BDU:2025-07865
CVE-2024-50340
DSA-5809-1
GHSA-X8VP-GF4Q-MW5J
USN-7272-1

Affected Products

Astra Linux
Debian
Linuxmint
Red Os
Symfony
Ubuntu