Description
symfony/runtime is a module for the Symphony PHP framework which enables decoupling PHP applications from global state. When the `register_argv_argc` php directive is set to `on` , and users call any URL with a special crafted query string, they are able to change the environment or debug mode used by the kernel when handling the request. As of versions 5.4.46, 6.4.14, and 7.1.7 the `SymfonyRuntime` now ignores the `argv` values for non-SAPI PHP runtimes. All users are advised to upgrade. There are no known workarounds for this vulnerability.
Published: 2024-11-06
Score: 7.3 High
EPSS: 85.6% High
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-5809-1 symfony security update
Github GHSA Github GHSA GHSA-x8vp-gf4q-mw5j Symfony allows changing the environment through a query
Ubuntu USN Ubuntu USN USN-7272-1 Symfony vulnerabilities
History

Thu, 07 Nov 2024 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Sensiolabs
Sensiolabs symfony
CPEs cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
Vendors & Products Sensiolabs
Sensiolabs symfony
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 06 Nov 2024 21:15:00 +0000

Type Values Removed Values Added
Description symfony/runtime is a module for the Symphony PHP framework which enables decoupling PHP applications from global state. When the `register_argv_argc` php directive is set to `on` , and users call any URL with a special crafted query string, they are able to change the environment or debug mode used by the kernel when handling the request. As of versions 5.4.46, 6.4.14, and 7.1.7 the `SymfonyRuntime` now ignores the `argv` values for non-SAPI PHP runtimes. All users are advised to upgrade. There are no known workarounds for this vulnerability.
Title Ability to change environment from query in symfony/runtime
Weaknesses CWE-74
References
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'}


Subscriptions

Sensiolabs Symfony
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2024-11-07T15:29:50.292Z

Reserved: 2024-10-22T17:54:40.955Z

Link: CVE-2024-50340

cve-icon Vulnrichment

Updated: 2024-11-07T15:29:44.749Z

cve-icon NVD

Status : Deferred

Published: 2024-11-06T21:15:05.527

Modified: 2026-04-15T00:35:42.020

Link: CVE-2024-50340

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses