Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v7mg-wg5h-pcx8

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

Multipart-file uploads call variables to be improperly registered in the global scope. In cases where variables are not declared explicitly before being used this can lead to unexpected behavior. This affects all supported versions of HHVM prior to the patch (3.25.1, 3.24.5, and 3.21.9 and below).

Multipart-file uploads call variables to be improperly registered in the global scope. In cases where variables are not declared explicitly before being used this can lead to unexpected behavior. This affects all supported versions of HHVM prior to the patch (3.25.1, 3.24.5, and 3.21.9 and below).

EPSS

Процентиль: 70%
0.0063
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-20
CWE-621

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 7 лет назад

Multipart-file uploads call variables to be improperly registered in the global scope. In cases where variables are not declared explicitly before being used this can lead to unexpected behavior. This affects all supported versions of HHVM prior to the patch (3.25.1, 3.24.5, and 3.21.9 and below).

CVSS3: 9.8
nvd
около 7 лет назад

Multipart-file uploads call variables to be improperly registered in the global scope. In cases where variables are not declared explicitly before being used this can lead to unexpected behavior. This affects all supported versions of HHVM prior to the patch (3.25.1, 3.24.5, and 3.21.9 and below).

CVSS3: 9.8
debian
около 7 лет назад

Multipart-file uploads call variables to be improperly registered in t ...

EPSS

Процентиль: 70%
0.0063
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-20
CWE-621