Описание
Due to an incomplete fix to CVE-2022-31629 https://github.com/advisories/GHSA-c43m-486j-j32p , network and same-site attackers can set a standard insecure cookie in the victim's browser which is treated as a __Host- or __Secure- cookie by PHP applications.
| Релиз | Статус | Примечание | 
|---|---|---|
| devel | DNE  | |
| esm-infra-legacy/trusty | needs-triage  | |
| esm-infra/focal | DNE  | |
| focal | DNE  | |
| jammy | DNE  | |
| mantic | DNE  | |
| noble | DNE  | |
| oracular | DNE  | |
| plucky | DNE  | |
| questing | DNE  | 
Показывать по
| Релиз | Статус | Примечание | 
|---|---|---|
| devel | DNE  | |
| esm-infra/focal | DNE  | |
| esm-infra/xenial | released  | 7.0.33-0ubuntu0.16.04.16+esm9 | 
| focal | DNE  | |
| jammy | DNE  | |
| mantic | DNE  | |
| noble | DNE  | |
| oracular | DNE  | |
| plucky | DNE  | |
| questing | DNE  | 
Показывать по
| Релиз | Статус | Примечание | 
|---|---|---|
| devel | DNE  | |
| esm-infra/bionic | released  | 7.2.24-0ubuntu0.18.04.17+esm3 | 
| esm-infra/focal | DNE  | |
| focal | DNE  | |
| jammy | DNE  | |
| mantic | DNE  | |
| noble | DNE  | |
| oracular | DNE  | |
| plucky | DNE  | |
| questing | DNE  | 
Показывать по
| Релиз | Статус | Примечание | 
|---|---|---|
| devel | DNE  | |
| esm-infra/focal | released  | 7.4.3-4ubuntu2.22 | 
| focal | released  | 7.4.3-4ubuntu2.22 | 
| jammy | DNE  | |
| mantic | DNE  | |
| noble | DNE  | |
| oracular | DNE  | |
| plucky | DNE  | |
| questing | DNE  | |
| upstream | needs-triage  | 
Показывать по
| Релиз | Статус | Примечание | 
|---|---|---|
| devel | DNE  | |
| esm-infra/focal | DNE  | |
| focal | DNE  | |
| jammy | released  | 8.1.2-1ubuntu2.17 | 
| mantic | DNE  | |
| noble | DNE  | |
| oracular | DNE  | |
| plucky | DNE  | |
| questing | DNE  | |
| upstream | released  | 8.1.28 | 
Показывать по
| Релиз | Статус | Примечание | 
|---|---|---|
| bionic | DNE  | |
| devel | DNE  | |
| esm-infra-legacy/trusty | DNE  | |
| esm-infra/focal | DNE  | |
| focal | DNE  | |
| jammy | DNE  | |
| mantic | released  | 8.2.10-2ubuntu2.1 | 
| noble | DNE  | |
| oracular | DNE  | |
| plucky | DNE  | 
Показывать по
| Релиз | Статус | Примечание | 
|---|---|---|
| bionic | DNE  | |
| devel | DNE  | |
| esm-infra-legacy/trusty | DNE  | |
| esm-infra/focal | DNE  | |
| focal | DNE  | |
| jammy | DNE  | |
| mantic | DNE  | |
| noble | released  | 8.3.6-0maysync1 | 
| oracular | released  | 8.3.6-0maysync1 | 
| plucky | DNE  | 
Показывать по
EPSS
6.5 Medium
CVSS3
Связанные уязвимости
Due to an incomplete fix to CVE-2022-31629 https://github.com/advisories/GHSA-c43m-486j-j32p , network and same-site attackers can set a standard insecure cookie in the victim's browser which is treated as a __Host- or __Secure- cookie by PHP applications.
Due to an incomplete fix to CVE-2022-31629 https://github.com/advisories/GHSA-c43m-486j-j32p , network and same-site attackers can set a standard insecure cookie in the victim's browser which is treated as a __Host- or __Secure- cookie by PHP applications.
Due to an incomplete fix to CVE-2022-31629 https://github.com/advisor ...
__Host-/__Secure- cookie bypass due to partial CVE-2022-31629 fix
EPSS
6.5 Medium
CVSS3