Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-5458

Опубликовано: 09 июн. 2024
Источник: nvd
CVSS3: 5.3
EPSS Низкий

Описание

In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, due to a code logic error, filtering functions such as filter_var when validating URLs (FILTER_VALIDATE_URL) for certain types of URLs the function will result in invalid user information (username + password part of URLs) being treated as valid user information. This may lead to the downstream code accepting invalid URLs as valid and parsing them incorrectly.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
Версия от 7.3.27 (включая) до 7.3.33 (включая)
cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
Версия от 7.4.15 (включая) до 7.4.33 (включая)
cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
Версия от 8.0.2 (включая) до 8.0.30 (включая)
cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
Версия от 8.1.0 (включая) до 8.1.29 (исключая)
cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
Версия от 8.2.0 (включая) до 8.2.20 (исключая)
cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
Версия от 8.3.0 (включая) до 8.3.8 (исключая)
Конфигурация 2
cpe:2.3:o:fedoraproject:fedora:40:*:*:*:*:*:*:*

EPSS

Процентиль: 52%
0.00287
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-345
CWE-345

Связанные уязвимости

CVSS3: 5.3
ubuntu
около 1 года назад

In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, due to a code logic error, filtering functions such as filter_var when validating URLs (FILTER_VALIDATE_URL) for certain types of URLs the function will result in invalid user information (username + password part of URLs) being treated as valid user information. This may lead to the downstream code accepting invalid URLs as valid and parsing them incorrectly.

CVSS3: 5.3
redhat
больше 2 лет назад

In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, due to a code logic error, filtering functions such as filter_var when validating URLs (FILTER_VALIDATE_URL) for certain types of URLs the function will result in invalid user information (username + password part of URLs) being treated as valid user information. This may lead to the downstream code accepting invalid URLs as valid and parsing them incorrectly.

CVSS3: 5.3
msrc
12 месяцев назад

Описание отсутствует

CVSS3: 5.3
debian
около 1 года назад

In PHP versions8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before ...

suse-cvrf
около 1 года назад

Security update for php8

EPSS

Процентиль: 52%
0.00287
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-345
CWE-345