Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-9026

Опубликовано: 08 окт. 2024
Источник: redhat
CVSS3: 3.3
EPSS Низкий

Описание

In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, when using PHP-FPM SAPI and it is configured to catch workers output through catch_workers_output = yes, it may be possible to pollute the final log or remove up to 4 characters from the log messages by manipulating log message content. Additionally, if PHP-FPM is configured to use syslog output, it may be possible to further remove log data using the same vulnerability.

A flaw was found in PHP-FPM, the FastCGI Process Manager. This vulnerability can allow an attacker to manipulate or remove up to 4 characters from log messages via crafted log content, potentially polluting or altering the final log. If PHP-FPM is configured to use syslog output, further log data manipulation is possible via the same vector.

Отчет

This vulnerability only affects configurations with the catch_workers_output directive enabled or set to yes in the configuration file. This option is disabled by default. Additionally, if the error_log directive is set to syslog, the logs are being sent to syslogd instead of a regular file, allowing further log data manipulation.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7phpOut of support scope
Red Hat Enterprise Linux 8php:8.0/phpFix deferred
Red Hat Enterprise Linux 8phpFixedRHSA-2024:1095111.12.2024
Red Hat Enterprise Linux 8phpFixedRHSA-2024:1095211.12.2024
Red Hat Enterprise Linux 9phpFixedRHSA-2024:1094911.12.2024
Red Hat Enterprise Linux 9phpFixedRHSA-2024:1095011.12.2024
Red Hat Enterprise Linux 9phpFixedRHSA-2025:731513.05.2025

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-117
Дефект:
CWE-158
https://bugzilla.redhat.com/show_bug.cgi?id=2317144php: PHP-FPM Log Manipulation Vulnerability

EPSS

Процентиль: 3%
0.00018
Низкий

3.3 Low

CVSS3

Связанные уязвимости

CVSS3: 3.3
ubuntu
8 месяцев назад

In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, when using PHP-FPM SAPI and it is configured to catch workers output through catch_workers_output = yes, it may be possible to pollute the final log or remove up to 4 characters from the log messages by manipulating log message content. Additionally, if PHP-FPM is configured to use syslog output, it may be possible to further remove log data using the same vulnerability.

CVSS3: 3.3
nvd
8 месяцев назад

In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, when using PHP-FPM SAPI and it is configured to catch workers output through catch_workers_output = yes, it may be possible to pollute the final log or remove up to 4 characters from the log messages by manipulating log message content. Additionally, if PHP-FPM is configured to use syslog output, it may be possible to further remove log data using the same vulnerability.

CVSS3: 3.3
msrc
8 месяцев назад

Описание отсутствует

CVSS3: 3.3
debian
8 месяцев назад

In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before ...

CVSS3: 3.3
github
9 месяцев назад

[PHP-FPM] Logs from childrens may be altered

EPSS

Процентиль: 3%
0.00018
Низкий

3.3 Low

CVSS3

Уязвимость CVE-2024-9026