PT-2024-8450 · Laravel+1 · Laravel+1
Taylorotwell
·
Published
2024-11-12
·
Updated
2026-01-03
·
CVE-2024-52301
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Laravel versions 6.20.45 through 11.31.0
Description
The issue is related to the register argc argv php directive being set to on, allowing users to change the environment used by the framework when handling requests with a special crafted query string. This can lead to unauthorized access and data tampering. More than 830,000 instances are potentially affected.
Recommendations
For versions 6.20.45 through 11.31.0, update to the latest version where the framework now ignores argv values for environment detection on non-cli SAPIs.
As a temporary workaround, consider setting the register argc argv php directive to off until a patch is available.
Restrict access to sensitive areas of the application to minimize the risk of exploitation.
Exploit
Fix
Argument Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Debian
Laravel