CVE-2024-24754
CVSS 3.1 Score 9.8 of 10 (high)
Details
Summary
CVE-2024-24754: The use of Bref, a serverless PHP deployment tool on Amazon Web Services Lambda, introduces a vulnerability when the Event-Driven Function runtime is employed and the handler follows the `RequestHandlerInterface`. In such cases, Lambda events are transformed into PSR7 objects, which may lead to inconsistencies during the conversion of MultiPart requests. These discrepancies might result in unintended behaviors and potential vulnerabilities due to the distinction in body parsing between Bref and plain PHP. This issue has been addressed in version 2.1.13.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.