Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2024-50342

Опубликовано: 06 нояб. 2024
Источник: ubuntu
Приоритет: medium
CVSS3: 3.1

Описание

symfony/http-client is a module for the Symphony PHP framework which provides powerful methods to fetch HTTP resources synchronously or asynchronously. When using the NoPrivateNetworkHttpClient, some internal information is still leaking during host resolution, which leads to possible IP/port enumeration. As of versions 5.4.46, 6.4.14, and 7.1.7 the NoPrivateNetworkHttpClient now filters blocked IPs earlier to prevent such leaks. All users are advised to upgrade. There are no known workarounds for this vulnerability.

РелизСтатусПримечание
devel

needs-triage

esm-apps/bionic

not-affected

code not present
esm-apps/focal

not-affected

code not present
esm-apps/jammy

released

5.4.4+dfsg-1ubuntu8+esm1
esm-apps/noble

released

6.4.5+dfsg-3ubuntu3+esm1
esm-apps/xenial

not-affected

code not present
focal

ignored

end of standard support, was needs-triage
jammy

needed

noble

needed

oracular

ignored

end of life, was needs-triage

Показывать по

3.1 Low

CVSS3

Связанные уязвимости

CVSS3: 3.1
nvd
9 месяцев назад

symfony/http-client is a module for the Symphony PHP framework which provides powerful methods to fetch HTTP resources synchronously or asynchronously. When using the `NoPrivateNetworkHttpClient`, some internal information is still leaking during host resolution, which leads to possible IP/port enumeration. As of versions 5.4.46, 6.4.14, and 7.1.7 the `NoPrivateNetworkHttpClient` now filters blocked IPs earlier to prevent such leaks. All users are advised to upgrade. There are no known workarounds for this vulnerability.

CVSS3: 3.1
debian
9 месяцев назад

symfony/http-client is a module for the Symphony PHP framework which p ...

CVSS3: 3.1
github
9 месяцев назад

Symfony allows internal address and port enumeration by NoPrivateNetworkHttpClient

CVSS3: 3.1
fstec
9 месяцев назад

Уязвимость компонента http-client программной платформы для разработки и управления веб-приложениями Symfony, позволяющая нарушителю получить доступ к конфиденциальным данным

CVSS3: 7.3
redos
около 1 месяца назад

Множественные уязвимости php-symfony4

3.1 Low

CVSS3