CVE-2024-52301

EUVD-2024-3258
Laravel is a web application framework. When the register_argc_argv php directive is set to on , and users call any URL with a special crafted query string, they are able to change the environment used by the framework when handling the request. The vulnerability fixed in 6.20.45, 7.30.7, 8.83.28, 9.52.17, 10.48.23, and 11.31.0. The framework now ignores argv values for environment detection on non-cli SAPIs.
Argument Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 98%
Affected Products (NVD)
VendorProductVersion
laravelframework
𝑥
< 6.20.45
laravelframework
7.0.0 ≤
𝑥
< 7.30.7
laravelframework
8.0.0 ≤
𝑥
< 8.83.28
laravelframework
9.0.0 ≤
𝑥
< 9.52.17
laravelframework
10.0.0 ≤
𝑥
< 10.48.23
laravelframework
11.0.0 ≤
𝑥
< 11.31.0
debiandebian_linux
11.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
php-laravel-framework
bookworm
vulnerable
bullseye
vulnerable
bullseye (security)
6.20.14+dfsg-2+deb11u2
fixed
forky
11.46.1+dfsg-4
fixed
sid
11.46.1+dfsg-4
fixed
trixie
10.48.29+dfsg-1
fixed