CVE-2024-52301
php-laravel-framework - security update
0.0
NONE
CVSS 3.1
EPSS 38.0%
描述
Laravel is a web application framework. When the register_argc_argv php directive is set to on , and users call any URL with a special crafted query string, they are able to change the environment used by the framework when handling the request. The vulnerability fixed in 6.20.45, 7.30.7, 8.83.28, 9.52.17, 10.48.23, and 11.31.0. The framework now ignores argv values for environment detection on non-cli SAPIs.
如何修補 CVE-2024-52301
要修補 CVE-2024-52301,請將受影響套件升級到下列已修補版本。
- —升級至 6.20.45 或更新版本
- —升級至 6.20.14+dfsg-2+deb11u2 或更新版本
- —升級至 6.20.14+dfsg-2+deb11u2 或更新版本
- —升級至 6.20.45 或更新版本
CVE-2024-52301 正在被利用嗎?
中等 — EPSS 為 38.0%,可持續追蹤但非最高優先。
受影響套件(4)
- from 0, < 6.20.45, >= 7.0.0, < 7.30.7, >= 8.0.0, < 8.83.28, >= 9.0.0, < 9.52.17, >= 10.0.0, < 10.48.23, >= 11.0.0, < 11.31.0
- from 0, < 6.20.14+dfsg-2+deb11u2
- from 0, < 6.20.14+dfsg-2+deb11u2
- from 0, < 6.20.45
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 4.0 | — | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N |
| osv | CVSS 3.1 | NONE0.0 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N |