CVE-2024-52301
HIGHDescription
Laravel is a web application framework. When the register_argc_argv php directive is set to on , and users call any URL with a special crafted query string, they are able to change the environment used by the framework when handling the request. The vulnerability fixed in 6.20.45, 7.30.7, 8.83.28, 9.52.17, 10.48.23, and 11.31.0. The framework now ignores argv values for environment detection on non-cli SAPIs.
Is your site exposed to CVE-2024-52301?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| laravel | framework |
| laravel | framework |
| laravel | framework |
| laravel | framework |
| laravel | framework |
| laravel | framework |
| debian | debian_linux |
References
Advisories & Patches
Other References
Frequently Asked Questions
What is CVE-2024-52301? +
How severe is CVE-2024-52301? +
What products are affected by CVE-2024-52301? +
How do I check if I'm vulnerable to CVE-2024-52301? +
Related Vulnerabilities
MCP Gateway allows easy and secure running and deployment of MCP servers. From 0.21.0 until 0.42.2, Docker MCP Gateway YAML-unmarshalled …
Argument injection in WP Toolkit for cPanel 6.11.2-10794 and earlier allows remote authenticated users to read arbitrary files and execute …
uniget is a universal installer and updater for (container) tools. Prior to 0.27.6, the hooks edit command in cmd/uniget/hooks.go parses …
Atril Document Viewer is the default document reader of the MATE desktop environment for Linux. A single-click remote code execution …
Repomix is a tool that packs repositories into AI-friendly files. Prior to 1.14.1, src/core/git/gitCommand.ts execGitShallowClone passes the --remote-branch value directly …
An argument parsing issue in OpenVPN 2.1_rc10 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows allows remote authenticated users to …