CVE-2024-50343 – Symfony/Validator Regular Expression Injection Vulnerability

CVE ID : CVE-2024-50343

Published : Nov. 6, 2024, 9:15 p.m. | 1 hour, 1 minute ago

Description : symfony/validator is a module for the Symphony PHP framework which provides tools to validate values. It is possible to trick a `Validator` configured with a regular expression using the `$` metacharacters, with an input ending with `n`. Symfony as of versions 5.4.43, 6.4.11, and 7.1.4 now uses the `D` regex modifier to match the entire input. Users are advised to upgrade. There are no known workarounds for this vulnerability.

Severity: 3.1 | LOW

Visit the link for more details, such as CVSS details, affected products, timeline, and more…

CVE-2024-50343 – Symfony/Validator Regular Expression Injection Vulnerability