cbcvebase.
CVE-2024-51996
published 2024-11-13

CVE-2024-51996: Symphony process is a module for the Symphony PHP framework which executes commands in sub-processes. When consuming a persisted remember-me cookie, Symfony…

PriorityP348high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
0.63%
46.3th percentile
Symphony process is a module for the Symphony PHP framework which executes commands in sub-processes. When consuming a persisted remember-me cookie, Symfony does not check if the username persisted in the database matches the username attached with the cookie, leading to authentication bypass. This vulnerability is fixed in 5.4.47, 6.4.15, and 7.1.8.

Affected

13 ranges
VendorProductVersion rangeFixed in
debiansymfony< symfony 5.4.23+dfsg-1+deb12u4 (bookworm)symfony 5.4.23+dfsg-1+deb12u4 (bookworm)
symfonysecurity-http>= 5.3.0 < 5.4.475.4.47
symfonysecurity-http>= 6.0.0-BETA1 < 6.4.156.4.15
symfonysecurity-http>= 7.0.0-BETA1 < 7.1.87.1.8
symfonysymfony
symfonysymfony
symfonysymfony
symfonysymfony>= 0 < 5.4.23+dfsg-1+deb12u45.4.23+dfsg-1+deb12u4
symfonysymfony>= 0 < 6.4.15+dfsg-16.4.15+dfsg-1
symfonysymfony>= 0 < 6.4.15+dfsg-16.4.15+dfsg-1
symfonysymfony>= 0 < 4.3.8+dfsg-1ubuntu1+esm24.3.8+dfsg-1ubuntu1+esm2
symfonysymfony>= 0 < 5.4.4+dfsg-1ubuntu8+esm15.4.4+dfsg-1ubuntu8+esm1
symfonysymfony>= 0 < 6.4.5+dfsg-3ubuntu3+esm16.4.5+dfsg-3ubuntu3+esm1

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
osv8.8HIGH
vendor_debian7.5HIGH
vendor_ubuntu5.9MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.