CVE-2024-52301

HIGHCVSS 8.7/10EPSS 37.98%

Last modified

CVE-2024-52301 is a high-severity vulnerability rated 8.7/10 on the CVSS scale. Laravel is a web application framework. When the register_argc_argv php directive is set to on , and users call any URL with a special crafted query string, they are able to change the environment used by the framework when handling the request. EPSS estimates a 37.98% chance of exploitation in the next 30 days.

Description

Laravel is a web application framework. When the register_argc_argv php directive is set to on , and users call any URL with a special crafted query string, they are able to change the environment used by the framework when handling the request. The vulnerability fixed in 6.20.45, 7.30.7, 8.83.28, 9.52.17, 10.48.23, and 11.31.0. The framework now ignores argv values for environment detection on non-cli SAPIs.

Metrics

CVSS 3.1
7.5/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

CVSS 4.0
8.7/10

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

EPSS Probability
37.98%

98.4th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
LaravelFramework< 6.20.45
LaravelFramework>= 7.0.0, < 7.30.7
LaravelFramework>= 8.0.0, < 8.83.28
LaravelFramework>= 9.0.0, < 9.52.17
LaravelFramework>= 10.0.0, < 10.48.23
LaravelFramework>= 11.0.0, < 11.31.0
DebianDebian Linux11.0

References

Timeline

Published
Last Modified
Status
Analyzed

Frequently Asked Questions

What is CVE-2024-52301?
Laravel is a web application framework. When the register_argc_argv php directive is set to on , and users call any URL with a special crafted query string, they are able to change the environment used by the framework when handling the request. The vulnerability fixed in 6.20.45, 7.30.7, 8.83.28, 9.52.17, 10.48.23, and 11.31.0. The framework now ignores argv values for environment detection on non-cli SAPIs.
How severe is CVE-2024-52301?
CVE-2024-52301 has a CVSS score of 8.7/10 (HIGH severity). The EPSS model estimates a 37.98% probability of exploitation in the next 30 days.
How do I fix CVE-2024-52301?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2024-52301?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST