← Voltar para CVEs
CVE-2024-50343
LOW3.1
Descricao
symfony/validator is a module for the Symphony PHP framework which provides tools to validate values. It is possible to trick a `Validator` configured with a regular expression using the `$` metacharacters, with an input ending with `\n`. Symfony as of versions 5.4.43, 6.4.11, and 7.1.4 now uses the `D` regex modifier to match the entire input. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Detalhes CVE
Pontuacao CVSS v3.13.1
SeveridadeLOW
Vetor CVSSCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
Vetor de ataqueNETWORK
ComplexidadeHIGH
Privilegios necessariosLOW
Interacao do usuarioNONE
Publicado11/6/2024
Ultima modificacao11/3/2025
Fontenvd
Avistamentos honeypot0
Fraquezas (CWE)
CWE-20
Referencias
https://github.com/symfony/symfony/commit/7d1032bbead9a4229b32fa6ebca32681c80cb76f(security-advisories@github.com)
https://github.com/symfony/symfony/security/advisories/GHSA-g3rh-rrhp-jhh9(security-advisories@github.com)
https://lists.debian.org/debian-lts-announce/2025/05/msg00051.html(af854a3a-2127-422b-91ae-364da2661108)
Correlacoes IOC
Sem correlacoes registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.