Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4687-m9rr-f6p3

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

HHVM, when used with FastCGI, would bind by default to all available interfaces. This behavior could allow a malicious individual unintended direct access to the application, which could result in information disclosure. This issue affects versions 4.3.0, 4.4.0, 4.5.0, 4.6.0, 4.7.0, 4.8.0, versions 3.30.5 and below, and all versions in the 4.0, 4.1, and 4.2 series.

HHVM, when used with FastCGI, would bind by default to all available interfaces. This behavior could allow a malicious individual unintended direct access to the application, which could result in information disclosure. This issue affects versions 4.3.0, 4.4.0, 4.5.0, 4.6.0, 4.7.0, 4.8.0, versions 3.30.5 and below, and all versions in the 4.0, 4.1, and 4.2 series.

EPSS

Процентиль: 58%
0.00366
Низкий

Дефекты

CWE-668

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 6 лет назад

HHVM, when used with FastCGI, would bind by default to all available interfaces. This behavior could allow a malicious individual unintended direct access to the application, which could result in information disclosure. This issue affects versions 4.3.0, 4.4.0, 4.5.0, 4.6.0, 4.7.0, 4.8.0, versions 3.30.5 and below, and all versions in the 4.0, 4.1, and 4.2 series.

CVSS3: 7.5
nvd
больше 6 лет назад

HHVM, when used with FastCGI, would bind by default to all available interfaces. This behavior could allow a malicious individual unintended direct access to the application, which could result in information disclosure. This issue affects versions 4.3.0, 4.4.0, 4.5.0, 4.6.0, 4.7.0, 4.8.0, versions 3.30.5 and below, and all versions in the 4.0, 4.1, and 4.2 series.

CVSS3: 7.5
debian
больше 6 лет назад

HHVM, when used with FastCGI, would bind by default to all available i ...

EPSS

Процентиль: 58%
0.00366
Низкий

Дефекты

CWE-668