CVE-2024-52301
Laravel allows environment manipulation via query string
Severity Score
8.7
*CVSS v4
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
Attend
*SSVC
Descriptions
Laravel is a web application framework. When the register_argc_argv php directive is set to on , and users call any URL with a special crafted query string, they are able to change the environment used by the framework when handling the request. The vulnerability fixed in 6.20.45, 7.30.7, 8.83.28, 9.52.17, 10.48.23, and 11.31.0. The framework now ignores argv values for environment detection on non-cli SAPIs.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Attack Requirements
Privileges Required
User Interaction
System
Vulnerable | Subsequent
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:Attend
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2024-11-06 CVE Reserved
- 2024-11-12 CVE Published
- 2024-11-13 EPSS Updated
- 2024-11-21 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-88: Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')
CAPEC
References (1)
URL | Tag | Source |
---|---|---|
https://github.com/laravel/framework/security/advisories/GHSA-gv7v-rgg6-548h | X_refsource_confirm |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Laravel Search vendor "Laravel" | Framework Search vendor "Laravel" for product "Framework" | < 6.20.45 Search vendor "Laravel" for product "Framework" and version " < 6.20.45" | en |
Affected
| ||||||
Laravel Search vendor "Laravel" | Framework Search vendor "Laravel" for product "Framework" | >= 7.0.0 < 7.30.7 Search vendor "Laravel" for product "Framework" and version " >= 7.0.0 < 7.30.7" | en |
Affected
| ||||||
Laravel Search vendor "Laravel" | Framework Search vendor "Laravel" for product "Framework" | >= 8.0.0 < 8.83.28 Search vendor "Laravel" for product "Framework" and version " >= 8.0.0 < 8.83.28" | en |
Affected
| ||||||
Laravel Search vendor "Laravel" | Framework Search vendor "Laravel" for product "Framework" | >= 9.0.0 < 9.52.17 Search vendor "Laravel" for product "Framework" and version " >= 9.0.0 < 9.52.17" | en |
Affected
| ||||||
Laravel Search vendor "Laravel" | Framework Search vendor "Laravel" for product "Framework" | >= 10.0.0 < 10.48.23 Search vendor "Laravel" for product "Framework" and version " >= 10.0.0 < 10.48.23" | en |
Affected
| ||||||
Laravel Search vendor "Laravel" | Framework Search vendor "Laravel" for product "Framework" | >= 11.0.0 < 11.31.0 Search vendor "Laravel" for product "Framework" and version " >= 11.0.0 < 11.31.0" | en |
Affected
|