GHSA-qq5c-677p-737q
Symfony vulnerable to command execution hijack on Windows with Process class
Quick fix
GHSA-qq5c-677p-737q — symfony/process: upgrade to the fixed version with the command below.
composer require symfony/process:^5.4.46Details
### Description
On Windows, when an executable file named `cmd.exe` is located in the current working directory it will be called by the `Process` class when preparing command arguments, leading to possible hijacking.
### Resolution
The `Process` class now uses the absolute path to `cmd.exe`.
The patch for this issue is available [here](https://github.com/symfony/symfony/commit/18ecd03eda3917fdf901a48e72518f911c64a1c9) for branch 5.4.
### Credits
We would like to thank Jordi Boggiano for reporting the issue and Nicolas Grekas for providing the fix.
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 5.4.46composer require symfony/process:^5.4.466.0.0Fixed in: 6.4.14composer require symfony/process:^6.4.147.0.0Fixed in: 7.1.7composer require symfony/process:^7.1.70Fixed in: 5.4.46composer require symfony/symfony:^5.4.466.0.0Fixed in: 6.4.14composer require symfony/symfony:^6.4.147.0.0Fixed in: 7.1.7composer require symfony/symfony:^7.1.7References
- https://github.com/symfony/symfony/security/advisories/GHSA-qq5c-677p-737q[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2024-51736[ADVISORY]
- https://github.com/symfony/symfony/commit/18ecd03eda3917fdf901a48e72518f911c64a1c9[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/process/CVE-2024-51736.yaml[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/symfony/CVE-2024-51736.yaml[WEB]
- https://github.com/symfony/symfony[PACKAGE]
- https://symfony.com/cve-2024-51736[WEB]