cbcvebase.
CVE-2024-2756
published 2024-04-29

CVE-2024-2756: Due to an incomplete fix to CVE-2022-31629 https://github.com/advisories/GHSA-c43m-486j-j32p , network and same-site attackers can set a standard insecure…

medium6.5CVSS 3.1
AVNACLPRNUIRSUCNIHAN
Due to an incomplete fix to CVE-2022-31629 https://github.com/advisories/GHSA-c43m-486j-j32p , network and same-site attackers can set a standard insecure cookie in the victim's browser which is treated as a __Host- or __Secure- cookie by PHP applications.

Affected

9 ranges
VendorProductVersion rangeFixed in
debianphp7.4< php7.4 7.4.33-1+deb11u5 (bullseye)php7.4 7.4.33-1+deb11u5 (bullseye)
debianphp8.2< php7.4 7.4.33-1+deb11u5 (bullseye)php7.4 7.4.33-1+deb11u5 (bullseye)
msrcazl3_php_8.3.12-1_on_azure_linux_3.0
msrcazure_linux_3.0_arm
msrcazure_linux_3.0_x64
msrccbl2_php_8.1.22-2_on_cbl_mariner_2.0
msrccbl2_php_8.1.28-1_on_cbl_mariner_2.0
msrccbl_mariner_2.0_arm
msrccbl_mariner_2.0_x64

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
osv6.5MEDIUM