CVE-2024-24754 is a critical vulnerability affecting Bref, a tool for running serverless PHP on AWS Lambda, specifically when using the Event-Driven Function runtime with a RequestHandlerInterface. It stems from an inconsistent parsing of multipart requests, where keys ending with an open square bracket lead to different outputs compared to plain PHP. This flaw carries a CVSS score of 9.8 (CRITICAL) due to its network-based attack vector, low complexity, and potential for complete compromise of confidentiality, integrity, and availability. While no active exploitation, public exploit code, or significant community discussion has been observed, the vulnerability has been patched in Bref version 2.1.13.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.1.13CPE matchmatch criteria | cpe:2.3:a:mnapoli:bref:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.