Описание
In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, due to a code logic error, filtering functions such as filter_var when validating URLs (FILTER_VALIDATE_URL) for certain types of URLs the function will result in invalid user information (username + password part of URLs) being treated as valid user information. This may lead to the downstream code accepting invalid URLs as valid and parsing them incorrectly.
| Релиз | Статус | Примечание | 
|---|---|---|
| devel | DNE  | |
| esm-infra-legacy/trusty | needs-triage  | |
| esm-infra/focal | DNE  | |
| focal | DNE  | |
| jammy | DNE  | |
| mantic | DNE  | |
| noble | DNE  | |
| oracular | DNE  | |
| plucky | DNE  | |
| questing | DNE  | 
Показывать по
| Релиз | Статус | Примечание | 
|---|---|---|
| devel | DNE  | |
| esm-infra/focal | DNE  | |
| esm-infra/xenial | released  | 7.0.33-0ubuntu0.16.04.16+esm11 | 
| focal | DNE  | |
| jammy | DNE  | |
| mantic | DNE  | |
| noble | DNE  | |
| oracular | DNE  | |
| plucky | DNE  | |
| questing | DNE  | 
Показывать по
| Релиз | Статус | Примечание | 
|---|---|---|
| devel | DNE  | |
| esm-infra/bionic | released  | 7.2.24-0ubuntu0.18.04.17+esm5 | 
| esm-infra/focal | DNE  | |
| focal | DNE  | |
| jammy | DNE  | |
| mantic | DNE  | |
| noble | DNE  | |
| oracular | DNE  | |
| plucky | DNE  | |
| questing | DNE  | 
Показывать по
| Релиз | Статус | Примечание | 
|---|---|---|
| devel | DNE  | |
| esm-infra/focal | released  | 7.4.3-4ubuntu2.23 | 
| focal | released  | 7.4.3-4ubuntu2.23 | 
| jammy | DNE  | |
| mantic | DNE  | |
| noble | DNE  | |
| oracular | DNE  | |
| plucky | DNE  | |
| questing | DNE  | |
| upstream | needs-triage  | 
Показывать по
| Релиз | Статус | Примечание | 
|---|---|---|
| devel | DNE  | |
| esm-infra/focal | DNE  | |
| focal | DNE  | |
| jammy | released  | 8.1.2-1ubuntu2.18 | 
| mantic | DNE  | |
| noble | DNE  | |
| oracular | DNE  | |
| plucky | DNE  | |
| questing | DNE  | |
| upstream | released  | 8.1.29 | 
Показывать по
| Релиз | Статус | Примечание | 
|---|---|---|
| devel | DNE  | |
| esm-infra/focal | DNE  | |
| focal | DNE  | |
| jammy | DNE  | |
| mantic | released  | 8.2.10-2ubuntu2.2 | 
| noble | DNE  | |
| oracular | DNE  | |
| plucky | DNE  | |
| questing | DNE  | |
| upstream | released  | 8.2.20 | 
Показывать по
| Релиз | Статус | Примечание | 
|---|---|---|
| devel | DNE  | |
| esm-infra/focal | DNE  | |
| focal | DNE  | |
| jammy | DNE  | |
| mantic | DNE  | |
| noble | released  | 8.3.6-0ubuntu0.24.04.1 | 
| oracular | released  | 8.3.9-1 | 
| plucky | DNE  | |
| questing | DNE  | |
| upstream | released  | 8.3.8 | 
Показывать по
Ссылки на источники
5.3 Medium
CVSS3
Связанные уязвимости
In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, due to a code logic error, filtering functions such as filter_var when validating URLs (FILTER_VALIDATE_URL) for certain types of URLs the function will result in invalid user information (username + password part of URLs) being treated as valid user information. This may lead to the downstream code accepting invalid URLs as valid and parsing them incorrectly.
In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, due to a code logic error, filtering functions such as filter_var when validating URLs (FILTER_VALIDATE_URL) for certain types of URLs the function will result in invalid user information (username + password part of URLs) being treated as valid user information. This may lead to the downstream code accepting invalid URLs as valid and parsing them incorrectly.
In PHP versions8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before ...
5.3 Medium
CVSS3