Количество 33
Количество 33
CVE-2023-3823
In PHP versions 8.0.* before 8.0.30, 8.1.* before 8.1.22, and 8.2.* before 8.2.8 various XML functions rely on libxml global state to track configuration variables, like whether external entities are loaded. This state is assumed to be unchanged unless the user explicitly changes it by calling appropriate function. However, since the state is process-global, other modules - such as ImageMagick - may also use this library within the same process, and change that global state for their internal purposes, and leave it in a state where external entities loading is enabled. This can lead to the situation where external XML is parsed with external entities loaded, which can lead to disclosure of any local files accessible to PHP. This vulnerable state may persist in the same process across many requests, until the process is shut down.
CVE-2023-3823
In PHP versions 8.0.* before 8.0.30, 8.1.* before 8.1.22, and 8.2.* before 8.2.8 various XML functions rely on libxml global state to track configuration variables, like whether external entities are loaded. This state is assumed to be unchanged unless the user explicitly changes it by calling appropriate function. However, since the state is process-global, other modules - such as ImageMagick - may also use this library within the same process, and change that global state for their internal purposes, and leave it in a state where external entities loading is enabled. This can lead to the situation where external XML is parsed with external entities loaded, which can lead to disclosure of any local files accessible to PHP. This vulnerable state may persist in the same process across many requests, until the process is shut down.
CVE-2023-3823
In PHP versions 8.0.* before 8.0.30, 8.1.* before 8.1.22, and 8.2.* before 8.2.8 various XML functions rely on libxml global state to track configuration variables, like whether external entities are loaded. This state is assumed to be unchanged unless the user explicitly changes it by calling appropriate function. However, since the state is process-global, other modules - such as ImageMagick - may also use this library within the same process, and change that global state for their internal purposes, and leave it in a state where external entities loading is enabled. This can lead to the situation where external XML is parsed with external entities loaded, which can lead to disclosure of any local files accessible to PHP. This vulnerable state may persist in the same process across many requests, until the process is shut down.
CVE-2023-3823
Security issue with external entity loading in XML without enabling it
CVE-2023-3823
In PHP versions 8.0.* before 8.0.30, 8.1.* before 8.1.22, and 8.2.* be ...
GHSA-3qrf-m4j2-pcrr
Security issue with external entity loading in XML without enabling it
BDU:2023-06656
Уязвимость интерпретатора языка программирования PHP, связанная с неверным ограничением XML-ссылок на внешний объект, позволяющая нарушителю вызвать отказ в обслуживании или получить несанкционированный доступ к конфиденциальным данным
SUSE-SU-2023:3541-1
Security update for php7
SUSE-SU-2023:3528-1
Security update for php7
SUSE-SU-2023:3498-1
Security update for php7
SUSE-SU-2023:3445-1
Security update for php7
ALT-PU-2023-8845
ALT-PU-2023-8845: package `php8.2` update to version 8.2.9-alt1
ALT-PU-2023-8844
ALT-PU-2023-8844: package `php8.1` update to version 8.1.22-alt1
ALT-PU-2023-8836
ALT-PU-2023-8836: package `php8.2-soap` update to version 8.2.9-alt1
ALT-PU-2023-8755
ALT-PU-2023-8755: package `php8.1-soap` update to version 8.1.22-alt1
ALT-PU-2023-8656
ALT-PU-2023-8656: package `php8.0-soap` update to version 8.0.30-alt1
ALT-PU-2023-8546
ALT-PU-2023-8546: package `php8.1-soap` update to version 8.1.23-alt1
ALT-PU-2023-8538
ALT-PU-2023-8538: package `php8.0-soap` update to version 8.0.30-alt1
ALT-PU-2023-8534
ALT-PU-2023-8534: package `php8.2-soap` update to version 8.2.9-alt1
ALT-PU-2023-8524
ALT-PU-2023-8524: package `php8.2` update to version 8.2.9-alt1
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2023-3823 In PHP versions 8.0.* before 8.0.30, 8.1.* before 8.1.22, and 8.2.* before 8.2.8 various XML functions rely on libxml global state to track configuration variables, like whether external entities are loaded. This state is assumed to be unchanged unless the user explicitly changes it by calling appropriate function. However, since the state is process-global, other modules - such as ImageMagick - may also use this library within the same process, and change that global state for their internal purposes, and leave it in a state where external entities loading is enabled. This can lead to the situation where external XML is parsed with external entities loaded, which can lead to disclosure of any local files accessible to PHP. This vulnerable state may persist in the same process across many requests, until the process is shut down. | CVSS3: 8.6 | 2% Низкий | около 3 лет назад | |
CVE-2023-3823 In PHP versions 8.0.* before 8.0.30, 8.1.* before 8.1.22, and 8.2.* before 8.2.8 various XML functions rely on libxml global state to track configuration variables, like whether external entities are loaded. This state is assumed to be unchanged unless the user explicitly changes it by calling appropriate function. However, since the state is process-global, other modules - such as ImageMagick - may also use this library within the same process, and change that global state for their internal purposes, and leave it in a state where external entities loading is enabled. This can lead to the situation where external XML is parsed with external entities loaded, which can lead to disclosure of any local files accessible to PHP. This vulnerable state may persist in the same process across many requests, until the process is shut down. | CVSS3: 7.5 | 2% Низкий | около 3 лет назад | |
CVE-2023-3823 In PHP versions 8.0.* before 8.0.30, 8.1.* before 8.1.22, and 8.2.* before 8.2.8 various XML functions rely on libxml global state to track configuration variables, like whether external entities are loaded. This state is assumed to be unchanged unless the user explicitly changes it by calling appropriate function. However, since the state is process-global, other modules - such as ImageMagick - may also use this library within the same process, and change that global state for their internal purposes, and leave it in a state where external entities loading is enabled. This can lead to the situation where external XML is parsed with external entities loaded, which can lead to disclosure of any local files accessible to PHP. This vulnerable state may persist in the same process across many requests, until the process is shut down. | CVSS3: 8.6 | 2% Низкий | около 3 лет назад | |
CVE-2023-3823 Security issue with external entity loading in XML without enabling it | CVSS3: 8.6 | 2% Низкий | около 1 месяца назад | |
CVE-2023-3823 In PHP versions 8.0.* before 8.0.30, 8.1.* before 8.1.22, and 8.2.* be ... | CVSS3: 8.6 | 2% Низкий | около 3 лет назад | |
GHSA-3qrf-m4j2-pcrr Security issue with external entity loading in XML without enabling it | CVSS3: 8.6 | 2% Низкий | около 3 лет назад | |
BDU:2023-06656 Уязвимость интерпретатора языка программирования PHP, связанная с неверным ограничением XML-ссылок на внешний объект, позволяющая нарушителю вызвать отказ в обслуживании или получить несанкционированный доступ к конфиденциальным данным | CVSS3: 8.6 | 2% Низкий | около 3 лет назад | |
SUSE-SU-2023:3541-1 Security update for php7 | около 3 лет назад | |||
SUSE-SU-2023:3528-1 Security update for php7 | около 3 лет назад | |||
SUSE-SU-2023:3498-1 Security update for php7 | около 3 лет назад | |||
SUSE-SU-2023:3445-1 Security update for php7 | около 3 лет назад | |||
ALT-PU-2023-8845 ALT-PU-2023-8845: package `php8.2` update to version 8.2.9-alt1 | CVSS3: 9.8 | около 3 лет назад | ||
ALT-PU-2023-8844 ALT-PU-2023-8844: package `php8.1` update to version 8.1.22-alt1 | CVSS3: 9.8 | около 3 лет назад | ||
ALT-PU-2023-8836 ALT-PU-2023-8836: package `php8.2-soap` update to version 8.2.9-alt1 | CVSS3: 9.8 | около 3 лет назад | ||
ALT-PU-2023-8755 ALT-PU-2023-8755: package `php8.1-soap` update to version 8.1.22-alt1 | CVSS3: 9.8 | около 3 лет назад | ||
ALT-PU-2023-8656 ALT-PU-2023-8656: package `php8.0-soap` update to version 8.0.30-alt1 | CVSS3: 9.8 | около 3 лет назад | ||
ALT-PU-2023-8546 ALT-PU-2023-8546: package `php8.1-soap` update to version 8.1.23-alt1 | CVSS3: 9.8 | почти 3 года назад | ||
ALT-PU-2023-8538 ALT-PU-2023-8538: package `php8.0-soap` update to version 8.0.30-alt1 | CVSS3: 9.8 | около 3 лет назад | ||
ALT-PU-2023-8534 ALT-PU-2023-8534: package `php8.2-soap` update to version 8.2.9-alt1 | CVSS3: 9.8 | около 3 лет назад | ||
ALT-PU-2023-8524 ALT-PU-2023-8524: package `php8.2` update to version 8.2.9-alt1 | CVSS3: 9.8 | около 3 лет назад |
Уязвимостей на страницу