CVE-2022-31629 — Improper Input Validation in Group PHP
Severity
6.5MEDIUMNVD
OSV5.5
EPSS
15.4%
top 5.34%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 28
Latest updateApr 12
Description
In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the vulnerability enables network and same-site attackers to set a standard insecure cookie in the victim's browser which is treated as a `__Host-` or `__Secure-` cookie by PHP applications.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:NExploitability: 2.8 | Impact: 3.6
Affected Packages2 packages
Also affects: Debian Linux 10.0, 11.0, Fedora 35, 36, 37