StackRadar

CVE-2024-51996

High

Advisory

Published 13 Nov 2024In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.006
48th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
20
of 17,781 indexed, latest versions
Container images
14
deployed by those charts
Fix available
1 of 1
affected package

Symfony has an Authentication Bypass via RememberMe

Carried by container images the latest versions of 20 of 17,781 indexed charts deploy, on 14 images.

Affected packageAffected versionsFixed inImages
symfony/security-httpcomposerv5.3.2, v5.3.6, v5.3.11, v5.4.0+2 more5.4.4714
OSV records
GHSA-cg23-qf8f-62rr

Charts affected

20 by stars
ChartLatestAffected imagesRadar Score
repmanszpadel-chartsVerified publisher3.52.171 of 3See more

repman szpadel-charts 3.52.17

1 of the 3 container images this version deploys carry CVE-2024-51996.

Container imageDigestPackageFixed in
buddy/repman:1.4.0097c897f8b54
symfony/security-http@v5.4.2
5.4.47

Open the chart page →

7,052
brpservicebrpservice1.1.01 of 4See more

brpservice brpservice 1.1.0

1 of the 4 container images this version deploys carry CVE-2024-51996.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/brpservice-php:latestc17f1ba17d36
symfony/security-http@v5.3.2
5.4.47

Open the chart page →

7,830
commonground-gatewaycommonground-gateway1.5.41 of 7See more

commonground-gateway commonground-gateway 1.5.4

1 of the 7 container images this version deploys carry CVE-2024-51996.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/commonground-gateway-php:latest947882bf2c37
symfony/security-http@v5.3.11
5.4.47

Open the chart page →

9,724
contactcataloguscontact-catalogus1.0.01 of 3See more

contactcatalogus contact-catalogus 1.0.0

1 of the 3 container images this version deploys carry CVE-2024-51996.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/contactcatalogus-php:latesteeb625bd660c
symfony/security-http@v5.4.8
5.4.47

Open the chart page →

7,303
digispoof-interfacedigispoof-interface1.0.01 of 3See more

digispoof-interface digispoof-interface 1.0.0

1 of the 3 container images this version deploys carry CVE-2024-51996.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/digispoof-interface-php:latest03aba499950f
symfony/security-http@v5.4.0
5.4.47

Open the chart page →

7,779
opencatalogiopencatalogi1.0.61 of 8See more

opencatalogi opencatalogi 1.0.6

1 of the 8 container images this version deploys carry CVE-2024-51996.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/commonground-gateway-php:latest947882bf2c37
symfony/security-http@v5.3.11
5.4.47

Open the chart page →

14,838
repmanrepman-helmchartVerified publisher1.0.121 of 3See more

repman repman-helmchart 1.0.12

1 of the 3 container images this version deploys carry CVE-2024-51996.

Container imageDigestPackageFixed in
buddy/repman:1.4.0097c897f8b54
symfony/security-http@v5.4.2
5.4.47

Open the chart page →

3,596
user-componentuser-component1.2.01 of 4See more

user-component user-component 1.2.0

1 of the 4 container images this version deploys carry CVE-2024-51996.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/user-component-php:latest198db44fabb5
symfony/security-http@v5.4.0
5.4.47

Open the chart page →

7,303
authorization-componentauthorization-component1.0.01 of 3See more

authorization-component authorization-component 1.0.0

1 of the 3 container images this version deploys carry CVE-2024-51996.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/authorization-component-php:latest94a749392fcf
symfony/security-http@v5.3.2
5.4.47

Open the chart page →

7,561
berichtserviceberichtservice1.0.01 of 3See more

berichtservice berichtservice 1.0.0

1 of the 3 container images this version deploys carry CVE-2024-51996.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/berichtservice-php:latestee6a21e66ff0
symfony/security-http@v5.4.8
5.4.47

Open the chart page →

7,342
commonground-gatewaycommonground-gateway-frontend0.1.51 of 4See more

commonground-gateway commonground-gateway-frontend 0.1.5

1 of the 4 container images this version deploys carry CVE-2024-51996.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/commonground-gateway-php:latest947882bf2c37
symfony/security-http@v5.3.11
5.4.47

Open the chart page →

2,825
eav-componenteav-component1.0.01 of 3See more

eav-component eav-component 1.0.0

1 of the 3 container images this version deploys carry CVE-2024-51996.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/eav-component-php:latest24bbca4a52a8
symfony/security-http@v5.4.8
5.4.47

Open the chart page →

7,255
education-componenteducation-component1.0.01 of 3See more

education-component education-component 1.0.0

1 of the 3 container images this version deploys carry CVE-2024-51996.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/education-component-php:latestda6b05a1a601
symfony/security-http@v5.4.8
5.4.47

Open the chart page →

7,327
logicservicelogicservice1.0.01 of 4See more

logicservice logicservice 1.0.0

1 of the 4 container images this version deploys carry CVE-2024-51996.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/logicservice-php:latest72aae2080595
symfony/security-http@v5.3.2
5.4.47

Open the chart page →

7,499
medewerkercatalogusmedewerkercatalogus1.0.01 of 3See more

medewerkercatalogus medewerkercatalogus 1.0.0

1 of the 3 container images this version deploys carry CVE-2024-51996.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/medewerkercatalogus-php:latest1ea5412bed26
symfony/security-http@v5.4.8
5.4.47

Open the chart page →

7,327
commonground-gatewayopencatalogi1.5.31 of 7See more

commonground-gateway opencatalogi 1.5.3

1 of the 7 container images this version deploys carry CVE-2024-51996.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/commonground-gateway-php:latest947882bf2c37
symfony/security-http@v5.3.11
5.4.47

Open the chart page →

9,724
commonground-gatewayskeleton-pip0.1.71 of 5See more

commonground-gateway skeleton-pip 0.1.7

1 of the 5 container images this version deploys carry CVE-2024-51996.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/commonground-gateway-php:latest947882bf2c37
symfony/security-http@v5.3.11
5.4.47

Open the chart page →

2,825
taalhuizen-servicetaalhuizen-service1.0.01 of 3See more

taalhuizen-service taalhuizen-service 1.0.0

1 of the 3 container images this version deploys carry CVE-2024-51996.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/taalhuizen-service-php:latest04f1b7f0d573
symfony/security-http@v5.3.6
5.4.47

Open the chart page →

7,480
repmanteam-blueVerified publisher0.3.01 of 5See more

repman team-blue 0.3.0

1 of the 5 container images this version deploys carry CVE-2024-51996.

Container imageDigestPackageFixed in
buddy/repman:1.4.0097c897f8b54
symfony/security-http@v5.4.2
5.4.47

Open the chart page →

3,993
webresourcecataloguswebresourcecatalogus1.1.01 of 4See more

webresourcecatalogus webresourcecatalogus 1.1.0

1 of the 4 container images this version deploys carry CVE-2024-51996.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/webresourcecatalogus-php:latest8f1bbd5cda85
symfony/security-http@v5.4.8
5.4.47

Open the chart page →

7,552

Container images carrying it

14 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/conductionnl/commonground-gateway-php:latest947882bf2c37
symfony/security-http@v5.3.11
5.4.47
5
buddy/repman:1.4.0097c897f8b54
symfony/security-http@v5.4.2
5.4.47
3
ghcr.io/conductionnl/authorization-component-php:latest94a749392fcf
symfony/security-http@v5.3.2
5.4.47
1
ghcr.io/conductionnl/berichtservice-php:latestee6a21e66ff0
symfony/security-http@v5.4.8
5.4.47
1
ghcr.io/conductionnl/brpservice-php:latestc17f1ba17d36
symfony/security-http@v5.3.2
5.4.47
1
ghcr.io/conductionnl/contactcatalogus-php:latesteeb625bd660c
symfony/security-http@v5.4.8
5.4.47
1
ghcr.io/conductionnl/digispoof-interface-php:latest03aba499950f
symfony/security-http@v5.4.0
5.4.47
1
ghcr.io/conductionnl/eav-component-php:latest24bbca4a52a8
symfony/security-http@v5.4.8
5.4.47
1
ghcr.io/conductionnl/education-component-php:latestda6b05a1a601
symfony/security-http@v5.4.8
5.4.47
1
ghcr.io/conductionnl/logicservice-php:latest72aae2080595
symfony/security-http@v5.3.2
5.4.47
1
ghcr.io/conductionnl/medewerkercatalogus-php:latest1ea5412bed26
symfony/security-http@v5.4.8
5.4.47
1
ghcr.io/conductionnl/taalhuizen-service-php:latest04f1b7f0d573
symfony/security-http@v5.3.6
5.4.47
1
ghcr.io/conductionnl/user-component-php:latest198db44fabb5
symfony/security-http@v5.4.0
5.4.47
1
ghcr.io/conductionnl/webresourcecatalogus-php:latest8f1bbd5cda85
symfony/security-http@v5.4.8
5.4.47
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.