CVE-2024-52301
HIGHDescription
Laravel is a web application framework. When the register_argc_argv php directive is set to on , and users call any URL with a special crafted query string, they are able to change the environment used by the framework when handling the request. The vulnerability fixed in 6.20.45, 7.30.7, 8.83.28, 9.52.17, 10.48.23, and 11.31.0. The framework now ignores argv values for environment detection on non-cli SAPIs.
Is your site exposed to CVE-2024-52301?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| laravel | framework |
| laravel | framework |
| laravel | framework |
| laravel | framework |
| laravel | framework |
| laravel | framework |
| debian | debian_linux |
References
Advisories & Patches
Other References
Frequently Asked Questions
What is CVE-2024-52301? +
How severe is CVE-2024-52301? +
What products are affected by CVE-2024-52301? +
How do I check if I'm vulnerable to CVE-2024-52301? +
Related Vulnerabilities
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Nomachine allows Argument Injection.This issue affects Nomachine: before …
Easywall 0.3.1 allows authenticated remote command execution via a command injection vulnerability in the /ports-save endpoint that suffers from a …
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in CRESTRON TOUCHSCREENS x70 allows Argument Injection.This issue affects …
Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like …
Repomix is a tool that packs repositories into AI-friendly files. Prior to 1.14.1, src/core/git/gitCommand.ts execGitShallowClone passes the --remote-branch value directly …
Atril Document Viewer is the default document reader of the MATE desktop environment for Linux. A single-click remote code execution …