CVE-2024-51996

unknown
Published 2024-11-13 · Modified 2024-11-15
CVSS v3
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS v2
VIR risk

Description

Symphony process is a module for the Symphony PHP framework which executes commands in sub-processes. When consuming a persisted remember-me cookie, Symfony does not check if the username persisted in the database matches the username attached with the cookie, leading to authentication bypass. This vulnerability is fixed in 5.4.47, 6.4.15, and 7.1.8.

Predictions

Exploit likelihood
30%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2024-51996

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed5.4.23+dfsg-1+deb12u4
debian debianbullseyefixed0
debian debianforkyfixed6.4.15+dfsg-1
debian debiansidfixed6.4.15+dfsg-1
debian debiantrixiefixed6.4.15+dfsg-1

Package impact

EcosystemPackageVulnerableFixed
php Packagistsymfony/security-http>=5.3.0,<5.4.475.4.47
php Packagistsymfony/security-http>=6.0.0-BETA1,<6.4.156.4.15
php Packagistsymfony/security-http>=7.0.0-BETA1,<7.1.87.1.8

References

Verify integrity in audit chain (admin only). AS-IS.