CVE-2024-50342 is a vulnerability in symfony/http-client, a module for the Symfony PHP framework, specifically affecting the NoPrivateNetworkHttpClient. It allows for IP/port enumeration due to internal information leakage during host resolution. This medium-severity vulnerability (CVSS 4.3) has a low impact on confidentiality and requires low privileges to exploit, with no integrity or availability impact. There is currently no known active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 5.4.46CPE matchmatch criteria | cpe:2.3:a:sensiolabs:httpclient:*:*:*:*:*:*:*:* | ||
>= 6.0.0, < 6.4.14CPE matchmatch criteria | cpe:2.3:a:sensiolabs:httpclient:*:*:*:*:*:*:*:* | ||
>= 7.0.0, < 7.1.7CPE matchmatch criteria | cpe:2.3:a:sensiolabs:httpclient:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.