cbcvebase.
CVE-2024-5458
published 2024-06-09

CVE-2024-5458: In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, due to a code logic error, filtering functions such as filter_var when validating…

PriorityP335medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
EPSS
12.12%
95.7th percentile
In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, due to a code logic error, filtering functions such as filter_var when validating URLs (FILTER_VALIDATE_URL) for certain types of URLs the function will result in invalid user information (username + password part of URLs) being treated as valid user information. This may lead to the downstream code accepting invalid URLs as valid and parsing them incorrectly.

Affected

16 ranges
VendorProductVersion rangeFixed in
debianphp7.4< php7.4 7.4.33-1+deb11u6 (bullseye)php7.4 7.4.33-1+deb11u6 (bullseye)
debianphp8.2< php7.4 7.4.33-1+deb11u6 (bullseye)php7.4 7.4.33-1+deb11u6 (bullseye)
fedoraprojectfedora
msrcazl3_php_8.3.6-1_on_azure_linux_3.0
msrcazl3_php_8.3.8-1_on_azure_linux_3.0
msrccbl2_php_8.1.28-1_on_cbl_mariner_2.0
msrccbl2_php_8.1.29-1_on_cbl_mariner_2.0
phpphp7.3.27 – 7.3.33
phpphp7.4.15 – 7.4.33
phpphp8.0.2 – 8.0.30
phpphp>= 8.1.0 < 8.1.298.1.29
phpphp>= 8.2.0 < 8.2.208.2.20
phpphp>= 8.3.0 < 8.3.88.3.8
php_groupphp>= 8.1.* < 8.1.298.1.29
php_groupphp>= 8.2.* < 8.2.208.2.20
php_groupphp>= 8.3.* < 8.3.88.3.8

CVSS provenance

nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
osv5.3MEDIUM
vendor_debian5.3MEDIUM
vendor_msrc5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.