CVE-2024-50342

LOW

symfony/http-client < 5.4.46 - Information Exposure via NoPrivateNetworkHttpClient

Title source: llm
STIX 2.1

Description

symfony/http-client is a module for the Symphony PHP framework which provides powerful methods to fetch HTTP resources synchronously or asynchronously. When using the `NoPrivateNetworkHttpClient`, some internal information is still leaking during host resolution, which leads to possible IP/port enumeration. As of versions 5.4.46, 6.4.14, and 7.1.7 the `NoPrivateNetworkHttpClient` now filters blocked IPs earlier to prevent such leaks. All users are advised to upgrade. There are no known workarounds for this vulnerability.

Scores

CVSS v3 3.1
EPSS 0.0048
EPSS Percentile 37.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-200
Status published
Products (3)
sensiolabs/httpclient < 5.4.46
symfony/http-client 4.3.0 - 5.4.47Packagist
symfony/symfony 4.3.0 - 5.4.47Packagist
Published Nov 06, 2024
Tracked Since Feb 18, 2026