CVE-2024-52301
Laravel is a web application framework. When the register_argc_argv php directive is set to on , and users call any URL with a special crafted query string, they are able to change the environment used by the framework when handling the request. The vulnerability fixed in 6.20.45, 7.30.7, 8.83.28, 9.52.17, 10.48.23, and 11.31.0. The framework now ignores argv values for environment detection on non-cli SAPIs.
CVSS
- Versión: 4.0
- Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Puntuación base: 8.7
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 45%
- Percentil entre todas las CVEs puntuadas: 99
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1190Exploit Public-Facing Applicationinitial access85 % - Impacto principal
T1565.001Stored Data Manipulationimpact75 % - Impacto secundario
T1574.007Path Interception by PATH Environment Variablestealth · execution70 %
Vulnerabilidad en Laravel explotable remotamente sin autenticación mediante query string manipulado (AV:N, PR:N, UI:N). VI:H indica manipulación de integridad: el atacante altera variables de entorno para cambiar el comportamiento del framework, afectando configuración y lógica de ejecución.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (2)
CWE
- CWE-88
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2024-52301",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-52301",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2024-11-13T14:51:08.466106Z"
}
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 3.9
}
],
"cvssMetricV40": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"cvssData": {
"Safety": "NOT_DEFINED",
"version": "4.0",
"Recovery": "NOT_DEFINED",
"baseScore": 8.7,
"Automatable": "NOT_DEFINED",
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"exploitMaturity": "NOT_DEFINED",
"providerUrgency": "NOT_DEFINED",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"privilegesRequired": "NONE",
"subIntegrityImpact": "NONE",
"vulnIntegrityImpact": "HIGH",
"integrityRequirement": "NOT_DEFINED",
"modifiedAttackVector": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"vulnAvailabilityImpact": "NONE",
"availabilityRequirement": "NOT_DEFINED",
"modifiedUserInteraction": "NOT_DEFINED",
"modifiedAttackComplexity": "NOT_DEFINED",
"subConfidentialityImpact": "NONE",
"vulnConfidentialityImpact": "NONE",
"confidentialityRequirement": "NOT_DEFINED",
"modifiedAttackRequirements": "NOT_DEFINED",
"modifiedPrivilegesRequired": "NOT_DEFINED",
"modifiedSubIntegrityImpact": "NOT_DEFINED",
"modifiedVulnIntegrityImpact": "NOT_DEFINED",
"vulnerabilityResponseEffort": "NOT_DEFINED",
"modifiedSubAvailabilityImpact": "NOT_DEFINED",
"modifiedVulnAvailabilityImpact": "NOT_DEFINED",
"modifiedSubConfidentialityImpact": "NOT_DEFINED",
"modifiedVulnConfidentialityImpact": "NOT_DEFINED"
}
}
]
},
"affected": [
{
"source": "security-advisories@github.com",
"affectedData": [
{
"vendor": "laravel",
"product": "framework",
"versions": [
{
"status": "affected",
"version": "< 6.20.45"
},
{
"status": "affected",
"version": ">= 7.0.0, < 7.30.7"
},
{
"status": "affected",
"version": ">= 8.0.0, < 8.83.28"
},
{
"status": "affected",
"version": ">= 9.0.0, < 9.52.17"
},
{
"status": "affected",
"version": ">= 10.0.0, < 10.48.23"
},
{
"status": "affected",
"version": ">= 11.0.0, < 11.31.0"
}
]
}
]
},
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"affectedData": [
{
"cpes": [
"cpe:2.3:a:laravel:framework:*:*:*:*:*:*:*:*"
],
"vendor": "laravel",
"product": "framework",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "6.20.45",
"versionType": "custom"
},
{
"status": "affected",
"version": "0",
"versionType": "custom",
"lessThanOrEqual": "7.0.0"
},
{
"status": "affected",
"version": "0",
"lessThan": "7.30.7",
"versionType": "custom"
},
{
"status": "affected",
"version": "0",
"versionType": "custom",
"lessThanOrEqual": "8.0.0"
},
{
"status": "affected",
"version": "0",
"lessThan": "8.83.28",
"versionType": "custom"
},
{
"status": "affected",
"version": "0",
"versionType": "custom",
"lessThanOrEqual": "9.0.0"
},
{
"status": "affected",
"version": "0",
"lessThan": "9.52.17",
"versionType": "custom"
},
{
"status": "affected",
"version": "0",
"versionType": "custom",
"lessThanOrEqual": "10.0.0"
},
{
"status": "affected",
"version": "0",
"lessThan": "10.48.23",
"versionType": "custom"
},
{
"status": "affected",
"version": "0",
"versionType": "custom",
"lessThanOrEqual": "11.0.0"
},
{
"status": "affected",
"version": "0",
"lessThan": "11.31.0",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
}
]
}
],
"published": "2024-11-12T20:15:14.087",
"references": [
{
"url": "https://github.com/laravel/framework/security/advisories/GHSA-gv7v-rgg6-548h",
"tags": [
"Vendor Advisory"
],
"source": "security-advisories@github.com"
},
{
"url": "https://lists.debian.org/debian-lts-announce/2024/12/msg00019.html",
"tags": [
"Mailing List",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"description": [
{
"lang": "en",
"value": "CWE-88"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Laravel is a web application framework. When the register_argc_argv php directive is set to on , and users call any URL with a special crafted query string, they are able to change the environment used by the framework when handling the request. The vulnerability fixed in 6.20.45, 7.30.7, 8.83.28, 9.52.17, 10.48.23, and 11.31.0. The framework now ignores argv values for environment detection on non-cli SAPIs."
},
{
"lang": "es",
"value": "Laravel es un framework de aplicaciones web. Cuando la directiva de php register_argc_argv está establecida en on y los usuarios llaman a cualquier URL con una cadena de consulta especialmente manipulada, pueden cambiar el entorno que utiliza el framework al procesar la solicitud. La vulnerabilidad se corrigió en 6.20.45, 7.30.7, 8.83.28, 9.52.17, 10.48.23 y 11.31.0. El framework ahora ignora los valores argv para la detección del entorno en SAPI que no son de CLI."
}
],
"lastModified": "2026-06-17T08:06:58.240",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:laravel:framework:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0E4D3C77-8967-41A0-B092-AE27DA385578",
"versionEndExcluding": "6.20.45"
},
{
"criteria": "cpe:2.3:a:laravel:framework:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "617A174E-7DE0-4145-BCE6-2A58CBBB6B21",
"versionEndExcluding": "7.30.7",
"versionStartIncluding": "7.0.0"
},
{
"criteria": "cpe:2.3:a:laravel:framework:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A506D04F-C9D9-4E37-B75F-29DA3943ECE0",
"versionEndExcluding": "8.83.28",
"versionStartIncluding": "8.0.0"
},
{
"criteria": "cpe:2.3:a:laravel:framework:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BB7F8265-5DF9-49A5-9D23-A459F16A948F",
"versionEndExcluding": "9.52.17",
"versionStartIncluding": "9.0.0"
},
{
"criteria": "cpe:2.3:a:laravel:framework:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9575B7A1-E291-4EC2-8557-ABCCACEB8622",
"versionEndExcluding": "10.48.23",
"versionStartIncluding": "10.0.0"
},
{
"criteria": "cpe:2.3:a:laravel:framework:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6346E858-7A00-4E7C-A3C2-8858C1D7C140",
"versionEndExcluding": "11.31.0",
"versionStartIncluding": "11.0.0"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FA6FEEC2-9F11-4643-8827-749718254FED"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security-advisories@github.com"
}