CVE-2024-28859 is a critical deserialization vulnerability affecting Symfony1, a community fork of symfony 1.4, specifically versions prior to 1.5.18. This flaw stems from a gadget chain within the bundled Swift Mailer dependency, allowing remote code execution if a developer deserializes untrusted user input. With a CVSS score of 9.0 (Critical), it presents a high impact on confidentiality, integrity, and availability, requiring high attack complexity but no user interaction. While there are no known active exploits or publicly available exploit tools, the vulnerability has garnered some community discussion and media coverage, including an article noting GPT-4's ability to exploit CVEs.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.3.0, < 1.5.18CPE matchmatch criteria | cpe:2.3:a:friendsofsymfony1:symfony1:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.4 Reddit, 1.2 Bluesky, 0.8 Mastodon, and 2.3 GitHub mentions.
The average CVE in this peer group has 0.8 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.