Логотип exploitDog
bind:"BDU:2023-06656" OR bind:"CVE-2023-3823"
Консоль
Логотип exploitDog

exploitDog

bind:"BDU:2023-06656" OR bind:"CVE-2023-3823"

Количество 17

Количество 17

fstec логотип

BDU:2023-06656

почти 2 года назад

Уязвимость интерпретатора языка программирования PHP, связанная с неверным ограничением XML-ссылок на внешний объект, позволяющая нарушителю вызвать отказ в обслуживании или получить несанкционированный доступ к конфиденциальным данным

CVSS3: 8.6
EPSS: Низкий
redos логотип

ROS-20240816-14

10 месяцев назад

Множественные уязвимости php

CVSS3: 9.8
EPSS: Низкий
redos логотип

ROS-20240816-08

10 месяцев назад

Множественные уязвимости php

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2023-3823

почти 2 года назад

In PHP versions 8.0.* before 8.0.30, 8.1.* before 8.1.22, and 8.2.* before 8.2.8 various XML functions rely on libxml global state to track configuration variables, like whether external entities are loaded. This state is assumed to be unchanged unless the user explicitly changes it by calling appropriate function. However, since the state is process-global, other modules - such as ImageMagick - may also use this library within the same process, and change that global state for their internal purposes, and leave it in a state where external entities loading is enabled. This can lead to the situation where external XML is parsed with external entities loaded, which can lead to disclosure of any local files accessible to PHP. This vulnerable state may persist in the same process across many requests, until the process is shut down.

CVSS3: 8.6
EPSS: Низкий
redhat логотип

CVE-2023-3823

почти 2 года назад

In PHP versions 8.0.* before 8.0.30, 8.1.* before 8.1.22, and 8.2.* before 8.2.8 various XML functions rely on libxml global state to track configuration variables, like whether external entities are loaded. This state is assumed to be unchanged unless the user explicitly changes it by calling appropriate function. However, since the state is process-global, other modules - such as ImageMagick - may also use this library within the same process, and change that global state for their internal purposes, and leave it in a state where external entities loading is enabled. This can lead to the situation where external XML is parsed with external entities loaded, which can lead to disclosure of any local files accessible to PHP. This vulnerable state may persist in the same process across many requests, until the process is shut down.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2023-3823

почти 2 года назад

In PHP versions 8.0.* before 8.0.30, 8.1.* before 8.1.22, and 8.2.* before 8.2.8 various XML functions rely on libxml global state to track configuration variables, like whether external entities are loaded. This state is assumed to be unchanged unless the user explicitly changes it by calling appropriate function. However, since the state is process-global, other modules - such as ImageMagick - may also use this library within the same process, and change that global state for their internal purposes, and leave it in a state where external entities loading is enabled. This can lead to the situation where external XML is parsed with external entities loaded, which can lead to disclosure of any local files accessible to PHP. This vulnerable state may persist in the same process across many requests, until the process is shut down.

CVSS3: 8.6
EPSS: Низкий
debian логотип

CVE-2023-3823

почти 2 года назад

In PHP versions 8.0.* before 8.0.30, 8.1.* before 8.1.22, and 8.2.* be ...

CVSS3: 8.6
EPSS: Низкий
github логотип

GHSA-3qrf-m4j2-pcrr

почти 2 года назад

Security issue with external entity loading in XML without enabling it

CVSS3: 8.6
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:3541-1

почти 2 года назад

Security update for php7

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:3528-1

почти 2 года назад

Security update for php7

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:3498-1

почти 2 года назад

Security update for php7

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:3445-1

почти 2 года назад

Security update for php7

EPSS: Низкий
rocky логотип

RLSA-2023:5926

больше 1 года назад

Important: php security update

EPSS: Низкий
oracle-oval логотип

ELSA-2024-0387

больше 1 года назад

ELSA-2024-0387: php:8.1 security update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2023-5927

больше 1 года назад

ELSA-2023-5927: php:8.0 security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2023-5926

больше 1 года назад

ELSA-2023-5926: php security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2024-10952

6 месяцев назад

ELSA-2024-10952: php:7.4 security update (MODERATE)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2023-06656

Уязвимость интерпретатора языка программирования PHP, связанная с неверным ограничением XML-ссылок на внешний объект, позволяющая нарушителю вызвать отказ в обслуживании или получить несанкционированный доступ к конфиденциальным данным

CVSS3: 8.6
0%
Низкий
почти 2 года назад
redos логотип
ROS-20240816-14

Множественные уязвимости php

CVSS3: 9.8
10 месяцев назад
redos логотип
ROS-20240816-08

Множественные уязвимости php

CVSS3: 9.8
10 месяцев назад
ubuntu логотип
CVE-2023-3823

In PHP versions 8.0.* before 8.0.30, 8.1.* before 8.1.22, and 8.2.* before 8.2.8 various XML functions rely on libxml global state to track configuration variables, like whether external entities are loaded. This state is assumed to be unchanged unless the user explicitly changes it by calling appropriate function. However, since the state is process-global, other modules - such as ImageMagick - may also use this library within the same process, and change that global state for their internal purposes, and leave it in a state where external entities loading is enabled. This can lead to the situation where external XML is parsed with external entities loaded, which can lead to disclosure of any local files accessible to PHP. This vulnerable state may persist in the same process across many requests, until the process is shut down.

CVSS3: 8.6
0%
Низкий
почти 2 года назад
redhat логотип
CVE-2023-3823

In PHP versions 8.0.* before 8.0.30, 8.1.* before 8.1.22, and 8.2.* before 8.2.8 various XML functions rely on libxml global state to track configuration variables, like whether external entities are loaded. This state is assumed to be unchanged unless the user explicitly changes it by calling appropriate function. However, since the state is process-global, other modules - such as ImageMagick - may also use this library within the same process, and change that global state for their internal purposes, and leave it in a state where external entities loading is enabled. This can lead to the situation where external XML is parsed with external entities loaded, which can lead to disclosure of any local files accessible to PHP. This vulnerable state may persist in the same process across many requests, until the process is shut down.

CVSS3: 7.5
0%
Низкий
почти 2 года назад
nvd логотип
CVE-2023-3823

In PHP versions 8.0.* before 8.0.30, 8.1.* before 8.1.22, and 8.2.* before 8.2.8 various XML functions rely on libxml global state to track configuration variables, like whether external entities are loaded. This state is assumed to be unchanged unless the user explicitly changes it by calling appropriate function. However, since the state is process-global, other modules - such as ImageMagick - may also use this library within the same process, and change that global state for their internal purposes, and leave it in a state where external entities loading is enabled. This can lead to the situation where external XML is parsed with external entities loaded, which can lead to disclosure of any local files accessible to PHP. This vulnerable state may persist in the same process across many requests, until the process is shut down.

CVSS3: 8.6
0%
Низкий
почти 2 года назад
debian логотип
CVE-2023-3823

In PHP versions 8.0.* before 8.0.30, 8.1.* before 8.1.22, and 8.2.* be ...

CVSS3: 8.6
0%
Низкий
почти 2 года назад
github логотип
GHSA-3qrf-m4j2-pcrr

Security issue with external entity loading in XML without enabling it

CVSS3: 8.6
0%
Низкий
почти 2 года назад
suse-cvrf логотип
SUSE-SU-2023:3541-1

Security update for php7

почти 2 года назад
suse-cvrf логотип
SUSE-SU-2023:3528-1

Security update for php7

почти 2 года назад
suse-cvrf логотип
SUSE-SU-2023:3498-1

Security update for php7

почти 2 года назад
suse-cvrf логотип
SUSE-SU-2023:3445-1

Security update for php7

почти 2 года назад
rocky логотип
RLSA-2023:5926

Important: php security update

больше 1 года назад
oracle-oval логотип
ELSA-2024-0387

ELSA-2024-0387: php:8.1 security update (MODERATE)

больше 1 года назад
oracle-oval логотип
ELSA-2023-5927

ELSA-2023-5927: php:8.0 security update (IMPORTANT)

больше 1 года назад
oracle-oval логотип
ELSA-2023-5926

ELSA-2023-5926: php security update (IMPORTANT)

больше 1 года назад
oracle-oval логотип
ELSA-2024-10952

ELSA-2024-10952: php:7.4 security update (MODERATE)

6 месяцев назад

Уязвимостей на страницу