A security issue in Symfony versions =6, =7, <7.1.7 of the Symfony Runtime component allows unauthorized access to sensitive resources.
When the register_argc_argv php directive is set to on , and users call any URL with a special crafted query string, they are able to change the environment or debug mode used by the kernel when handling the request.
The vulnerability is easy to exploit remotely. Although assigned a 7.3 CVSS score, IONIX research team witnesses several vulnerable instances that leaked critically sensitive information.
References:

