CVE-2024-50345

Source
https://cve.org/CVERecord?id=CVE-2024-50345
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-50345.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-50345
Aliases
Downstream
Published
2024-11-06T20:56:21.062Z
Modified
2026-02-13T02:44:51.090530Z
Severity
  • 3.1 (Low) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N CVSS Calculator
Summary
Open redirect via browser-sanitized URLs in symfony/http-foundation
Details

symfony/http-foundation is a module for the Symphony PHP framework which defines an object-oriented layer for the HTTP specification. The Request class, does not parse URI with special characters the same way browsers do. As a result, an attacker can trick a validator relying on the Request class to redirect users to another domain. The Request::create methods now assert the URI does not contain invalid characters as defined by https://url.spec.whatwg.org/. This issue has been patched in versions 5.4.46, 6.4.14, and 7.1.7. Users are advised to upgrade. There are no known workarounds for this vulnerability.

Database specific
{
    "cwe_ids": [
        "CWE-601"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/50xxx/CVE-2024-50345.json",
    "cna_assigner": "GitHub_M"
}
References

Affected packages

Git / github.com/symfony/security-http

Affected ranges

Affected versions

v4.*
v4.4.36
v4.4.37
v4.4.41
v4.4.42
v4.4.44
v4.4.48
v4.4.50
v5.*
v5.3.13
v5.3.14
v5.4.10
v5.4.11
v5.4.12
v5.4.13
v5.4.15
v5.4.17
v5.4.19
v5.4.2
v5.4.20
v5.4.21
v5.4.22
v5.4.23
v5.4.26
v5.4.28
v5.4.3
v5.4.30
v5.4.31
v5.4.35
v5.4.36
v5.4.38
v5.4.39
v5.4.40
v5.4.41
v5.4.43
v5.4.44
v5.4.45
v5.4.46
v5.4.5
v5.4.8
v5.4.9
v6.*
v6.0.0
v6.0.1
v6.0.10
v6.0.11
v6.0.12
v6.0.13
v6.0.14
v6.0.15
v6.0.17
v6.0.19
v6.0.2
v6.0.20
v6.0.3
v6.0.5
v6.0.7
v6.0.8
v6.0.9
v6.1.0
v6.1.0-BETA1
v6.1.0-BETA2
v6.1.0-RC1
v6.1.1
v6.1.11
v6.1.12
v6.1.2
v6.1.3
v6.1.4
v6.1.5
v6.1.6
v6.1.7
v6.1.9
v6.2.0
v6.2.0-BETA1
v6.2.0-BETA3
v6.2.0-RC1
v6.2.10
v6.2.11
v6.2.13
v6.2.2
v6.2.5
v6.2.6
v6.2.7
v6.2.8
v6.3.0
v6.3.0-BETA1
v6.3.0-RC1
v6.3.1
v6.3.12
v6.3.2
v6.3.4
v6.3.5
v6.3.6
v6.3.8
v6.4.0
v6.4.0-BETA1
v6.4.0-BETA3
v6.4.0-RC1
v6.4.0-RC2
v6.4.11
v6.4.12
v6.4.13
v6.4.3
v6.4.4
v6.4.7
v6.4.8
v6.4.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-50345.json"

Git / github.com/symfony/symfony

Affected ranges

Type
GIT
Repo
https://github.com/symfony/symfony
Events

Affected versions

v4.*
v4.4.36
v4.4.37
v4.4.38
v4.4.39
v4.4.40
v4.4.41
v4.4.42
v4.4.43
v4.4.44
v4.4.45
v4.4.46
v4.4.47
v4.4.48
v4.4.49
v4.4.50
v4.4.51
v5.*
v5.3.13
v5.3.14
v5.3.15
v5.3.16
v5.4.0
v5.4.1
v5.4.10
v5.4.11
v5.4.12
v5.4.13
v5.4.14
v5.4.15
v5.4.16
v5.4.17
v5.4.18
v5.4.19
v5.4.2
v5.4.20
v5.4.21
v5.4.22
v5.4.23
v5.4.24
v5.4.25
v5.4.26
v5.4.27
v5.4.28
v5.4.29
v5.4.3
v5.4.30
v5.4.31
v5.4.32
v5.4.33
v5.4.34
v5.4.35
v5.4.36
v5.4.37
v5.4.38
v5.4.39
v5.4.4
v5.4.40
v5.4.41
v5.4.42
v5.4.43
v5.4.44
v5.4.45
v5.4.5
v5.4.6
v5.4.7
v5.4.8
v5.4.9
v6.*
v6.0.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-50345.json"