CVE-2024-5458
published 2024-06-09CVE-2024-5458: In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, due to a code logic error, filtering functions such as filter_var when validating…
PriorityP335medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
EPSS
12.12%
95.7th percentile
In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, due to a code logic error, filtering functions such as filter_var when validating URLs (FILTER_VALIDATE_URL) for certain types of URLs the function will result in invalid user information (username + password part of URLs) being treated as valid user information. This may lead to the downstream code accepting invalid URLs as valid and parsing them incorrectly.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | php7.4 | < php7.4 7.4.33-1+deb11u6 (bullseye) | php7.4 7.4.33-1+deb11u6 (bullseye) |
| debian | php8.2 | < php7.4 7.4.33-1+deb11u6 (bullseye) | php7.4 7.4.33-1+deb11u6 (bullseye) |
| fedoraproject | fedora | — | — |
| msrc | azl3_php_8.3.6-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_php_8.3.8-1_on_azure_linux_3.0 | — | — |
| msrc | cbl2_php_8.1.28-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_php_8.1.29-1_on_cbl_mariner_2.0 | — | — |
| php | php | 7.3.27 – 7.3.33 | — |
| php | php | 7.4.15 – 7.4.33 | — |
| php | php | 8.0.2 – 8.0.30 | — |
| php | php | >= 8.1.0 < 8.1.29 | 8.1.29 |
| php | php | >= 8.2.0 < 8.2.20 | 8.2.20 |
| php | php | >= 8.3.0 < 8.3.8 | 8.3.8 |
| php_group | php | >= 8.1.* < 8.1.29 | 8.1.29 |
| php_group | php | >= 8.2.* < 8.2.20 | 8.2.20 |
| php_group | php | >= 8.3.* < 8.3.8 | 8.3.8 |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
osv5.3MEDIUM
vendor_debian5.3MEDIUM
vendor_msrc5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
PHP vulnerability
vendor_ubuntu·2024-09-09
CVE-2024-5458 PHP vulnerability
Title: PHP vulnerability
Summary: PHP could be made to accept invalid URLs.
USN-6841-1 fixed a vulnerability in PHP. This update provides the
corresponding updates for Ubuntu 16.04 LTS and Ubuntu 18.04 LTS.
Original advisory details:
It was discovered that PHP could early return in the filter_var function
resulting in invalid user information being treated as valid user
information. An attacker could possibly use this issue to expose raw
user input information.
Instructions: In general, a standard system update will make all the necessary changes.
Microsoft
Filter bypass in filter_var (FILTER_VALIDATE_URL)
vendor_msrc·2024-06-11·CVSS 5.3
CVE-2024-5458 [MEDIUM] CWE-345 Filter bypass in filter_var (FILTER_VALIDATE_URL)
Filter bypass in filter_var (FILTER_VALIDATE_URL)
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
php: php
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn.microsoft
Debian
CVE-2024-5458: php7.4 - In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, du...
vendor_debian·2024·CVSS 5.3
CVE-2024-5458 [MEDIUM] CVE-2024-5458: php7.4 - In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, du...
In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, due to a code logic error, filtering functions such as filter_var when validating URLs (FILTER_VALIDATE_URL) for certain types of URLs the function will result in invalid user information (username + password part of URLs) being treated as valid user information. This may lead to the downstream code accepting invalid URLs as valid and parsing them incorrectly.
Scope: local
bullseye: resolved (fixed in 7.4.33-1+deb11u6)
Red Hat
php: Filter bypass in filter_var (FILTER_VALIDATE_URL)
vendor_redhat·2022-10-21·CVSS 5.3
CVE-2024-5458 [MEDIUM] CWE-20 php: Filter bypass in filter_var (FILTER_VALIDATE_URL)
php: Filter bypass in filter_var (FILTER_VALIDATE_URL)
In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, due to a code logic error, filtering functions such as filter_var when validating URLs (FILTER_VALIDATE_URL) for certain types of URLs the function will result in invalid user information (username + password part of URLs) being treated as valid user information. This may lead to the downstream code accepting invalid URLs as valid and parsing them incorrectly.
A flaw was found in PHP. An early return in the filter_var (FILTER_VALIDATE_URL) function results in invalid user information (username + password part of URLs) being treated as valid user information. This issue impacts users who expect only completely valid URLs to be returned by filter_var (FILTER_
OSV
CVE-2024-5458: In PHP versions 8
osv·2024-06-09·CVSS 5.3
CVE-2024-5458 [MEDIUM] CVE-2024-5458: In PHP versions 8
In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, due to a code logic error, filtering functions such as filter_var when validating URLs (FILTER_VALIDATE_URL) for certain types of URLs the function will result in invalid user information (username + password part of URLs) being treated as valid user information. This may lead to the downstream code accepting invalid URLs as valid and parsing them incorrectly.
No detection rules found.
No writeups or analysis indexed.
http://www.openwall.com/lists/oss-security/2024/06/07/1https://github.com/php/php-src/security/advisories/GHSA-w8qr-v226-r27whttps://lists.debian.org/debian-lts-announce/2024/06/msg00009.htmlhttps://lists.fedoraproject.org/archives/list/[email protected]/message/PKGTQUOA2NTZ3RXN22CSAUJPIRUYRB4B/https://lists.fedoraproject.org/archives/list/[email protected]/message/W45DBOH56NQDRTOM2DN2LNA2FZIMC3PK/https://security.netapp.com/advisory/ntap-20240726-0001/http://www.openwall.com/lists/oss-security/2024/06/07/1https://github.com/php/php-src/security/advisories/GHSA-w8qr-v226-r27whttps://lists.debian.org/debian-lts-announce/2024/06/msg00009.htmlhttps://lists.debian.org/debian-lts-announce/2024/10/msg00011.htmlhttps://lists.fedoraproject.org/archives/list/[email protected]/message/PKGTQUOA2NTZ3RXN22CSAUJPIRUYRB4B/https://lists.fedoraproject.org/archives/list/[email protected]/message/W45DBOH56NQDRTOM2DN2LNA2FZIMC3PK/https://security.netapp.com/advisory/ntap-20240726-0001/
2024-06-09
Published