symfony/runtime is a module for the Symphony PHP framework which enables decoupling PHP applications from global state. When the `register_argv_argc` php directive is set to `on` , and users call any URL with a special crafted query string, they are able to change the environment or debug mode used by the kernel when handling the request. As of versions 5.4.46, 6.4.14, and 7.1.7 the `SymfonyRuntime` now ignores the `argv` values for non-SAPI PHP runtimes. All users are advised to upgrade. There are no known workarounds for this vulnerability.

Project Subscriptions

Vendors Products
Sensiolabs Subscribe
Symfony Subscribe
Advisories
Source ID Title
Debian DSA Debian DSA DSA-5809-1 symfony security update
Github GHSA Github GHSA GHSA-x8vp-gf4q-mw5j Symfony allows changing the environment through a query
Ubuntu USN Ubuntu USN USN-7272-1 Symfony vulnerabilities
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 07 Nov 2024 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Sensiolabs
Sensiolabs symfony
CPEs cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
Vendors & Products Sensiolabs
Sensiolabs symfony
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 06 Nov 2024 21:15:00 +0000

Type Values Removed Values Added
Description symfony/runtime is a module for the Symphony PHP framework which enables decoupling PHP applications from global state. When the `register_argv_argc` php directive is set to `on` , and users call any URL with a special crafted query string, they are able to change the environment or debug mode used by the kernel when handling the request. As of versions 5.4.46, 6.4.14, and 7.1.7 the `SymfonyRuntime` now ignores the `argv` values for non-SAPI PHP runtimes. All users are advised to upgrade. There are no known workarounds for this vulnerability.
Title Ability to change environment from query in symfony/runtime
Weaknesses CWE-74
References
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2024-11-07T15:29:50.292Z

Reserved: 2024-10-22T17:54:40.955Z

Link: CVE-2024-50340

cve-icon Vulnrichment

Updated: 2024-11-07T15:29:44.749Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-11-06T21:15:05.527

Modified: 2024-11-08T19:01:25.633

Link: CVE-2024-50340

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses