The upstream Symfony process module version required updating to remove a command injection risk on Windows systems.
| Severity/Risk: | Serious |
| Versions affected: | 4.5 to 4.5.8 |
| Versions fixed: | 4.5.9 |
| Reported by: | Dustin Frank |
| CVE identifier: | CVE-2024-51736 |
| Changes (4.5.9): | https://github.com/moodle/moodle/commit/3cf9457a36f5c5583ce5fdf6e3836d3d272289a8 |
| Tracker issue: | MDL-87594 Update Symfony process module version to avoid a security risk (upstream) |