Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-1734

Опубликовано: 30 мар. 2025
Источник: nvd
CVSS3: 5.3
EPSS Низкий

Описание

In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when receiving headers from HTTP server, the headers missing a colon (:) are treated as valid headers even though they are not. This may confuse applications into accepting invalid headers.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
Версия от 8.1.0 (включая) до 8.1.32 (исключая)
cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
Версия от 8.2.0 (включая) до 8.2.28 (исключая)
cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
Версия от 8.3.0 (включая) до 8.3.19 (исключая)
cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
Версия от 8.4.0 (включая) до 8.4.5 (исключая)
Конфигурация 2
cpe:2.3:a:netapp:ontap:9:*:*:*:*:*:*:*

EPSS

Процентиль: 35%
0.00139
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 5.3
ubuntu
4 месяца назад

In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when receiving headers from HTTP server, the headers missing a colon (:) are treated as valid headers even though they are not. This may confuse applications into accepting invalid headers.

CVSS3: 3.7
redhat
4 месяца назад

In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when receiving headers from HTTP server, the headers missing a colon (:) are treated as valid headers even though they are not. This may confuse applications into accepting invalid headers.

CVSS3: 5.3
msrc
4 месяца назад

Описание отсутствует

CVSS3: 5.3
debian
4 месяца назад

In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* ...

github
5 месяцев назад

Streams HTTP wrapper does not fail for headers with invalid name and no colon

EPSS

Процентиль: 35%
0.00139
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-20