Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-31629

Опубликовано: 28 сент. 2022
Источник: debian

Описание

In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the vulnerability enables network and same-site attackers to set a standard insecure cookie in the victim's browser which is treated as a `__Host-` or `__Secure-` cookie by PHP applications.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
php8.1fixed8.1.12-1package
php7.4removedpackage
php7.3removedpackage

Примечания

  • Fixed in 8.1.11, 7.4.32

  • PHP Bug: https://bugs.php.net/bug.php?id=81727

  • https://github.com/php/php-src/commit/0611be4e82887cee0de6c4cbae320d34eec946ca

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 2 лет назад

In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the vulnerability enables network and same-site attackers to set a standard insecure cookie in the victim's browser which is treated as a `__Host-` or `__Secure-` cookie by PHP applications.

CVSS3: 6.5
redhat
больше 2 лет назад

In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the vulnerability enables network and same-site attackers to set a standard insecure cookie in the victim's browser which is treated as a `__Host-` or `__Secure-` cookie by PHP applications.

CVSS3: 6.5
nvd
больше 2 лет назад

In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the vulnerability enables network and same-site attackers to set a standard insecure cookie in the victim's browser which is treated as a `__Host-` or `__Secure-` cookie by PHP applications.

CVSS3: 6.5
redos
11 месяцев назад

Уязвимость php

CVSS3: 6.5
github
больше 2 лет назад

In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the vulnerability enables network and same-site attackers to set a standard insecure cookie in the victim's browser which is treated as a `__Host-` or `__Secure-` cookie by PHP applications.