cbcvebase.
CVE-2024-50343
published 2024-11-06

CVE-2024-50343: symfony/validator is a module for the Symphony PHP framework which provides tools to validate values. It is possible to trick a `Validator` configured with a…

PriorityP412low3.1CVSS 3.1
AVNACHPRLUINSUCLINAN
EPSS
0.46%
37.4th percentile
symfony/validator is a module for the Symphony PHP framework which provides tools to validate values. It is possible to trick a `Validator` configured with a regular expression using the `$` metacharacters, with an input ending with `\n`. Symfony as of versions 5.4.43, 6.4.11, and 7.1.4 now uses the `D` regex modifier to match the entire input. Users are advised to upgrade. There are no known workarounds for this vulnerability.

Affected

17 ranges
VendorProductVersion rangeFixed in
debiansymfony< symfony 5.4.23+dfsg-1+deb12u3 (bookworm)symfony 5.4.23+dfsg-1+deb12u3 (bookworm)
symfonysymfony< 5.4.435.4.43
symfonysymfony
symfonysymfony
symfonysymfony>= 0 < 4.4.19+dfsg-2+deb11u74.4.19+dfsg-2+deb11u7
symfonysymfony>= 0 < 5.4.23+dfsg-1+deb12u35.4.23+dfsg-1+deb12u3
symfonysymfony>= 0 < 6.4.11+dfsg-16.4.11+dfsg-1
symfonysymfony>= 0 < 6.4.11+dfsg-16.4.11+dfsg-1
symfonysymfony>= 0 < 5.4.435.4.43
symfonysymfony>= 0 < 4.3.8+dfsg-1ubuntu1+esm24.3.8+dfsg-1ubuntu1+esm2
symfonysymfony>= 0 < 5.4.4+dfsg-1ubuntu8+esm15.4.4+dfsg-1ubuntu8+esm1
symfonysymfony>= 0 < 6.4.5+dfsg-3ubuntu3+esm16.4.5+dfsg-3ubuntu3+esm1
symfonysymfony>= 6.0.0 < 6.4.116.4.11
symfonysymfony>= 7.0.0 < 7.1.47.1.4
symfonyvalidator>= 0 < 5.4.435.4.43
symfonyvalidator>= 6.0.0 < 6.4.116.4.11
symfonyvalidator>= 7.0.0 < 7.1.47.1.4

CVSS provenance

nvdv3.13.1LOWCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
osv8.8HIGH
vendor_ubuntu5.9MEDIUM
vendor_debian3.1LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.