PT-2024-8450 · Laravel+1 · Laravel+1

Taylorotwell

·

Published

2024-11-12

·

Updated

2026-01-03

·

CVE-2024-52301

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Laravel versions 6.20.45 through 11.31.0
Description The issue is related to the register argc argv php directive being set to on, allowing users to change the environment used by the framework when handling requests with a special crafted query string. This can lead to unauthorized access and data tampering. More than 830,000 instances are potentially affected.
Recommendations For versions 6.20.45 through 11.31.0, update to the latest version where the framework now ignores argv values for environment detection on non-cli SAPIs. As a temporary workaround, consider setting the register argc argv php directive to off until a patch is available. Restrict access to sensitive areas of the application to minimize the risk of exploitation.

Exploit

Fix

Argument Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-10010
BIT-LARAVEL-2024-52301
CVE-2024-52301
DLA-3997-1
GHSA-GV7V-RGG6-548H

Affected Products

Debian
Laravel