Skip to content

CVE-2024-2756 (Medium) detected in php-srcphp-8.2.4 #166

@mend-bolt-for-github

Description

@mend-bolt-for-github

CVE-2024-2756 - Medium Severity Vulnerability

Vulnerable Library - php-srcphp-8.2.4

The PHP Interpreter

Library home page: https://github.com/php/php-src.git

Found in base branch: master

Vulnerable Source Files (1)

/main/php_variables.c

Vulnerability Details

Due to an incomplete fix to CVE-2022-31629 GHSA-c43m-486j-j32p , network and same-site attackers can set a standard insecure cookie in the victim's browser which is treated as a __Host- or __Secure- cookie by PHP applications. 

Publish Date: 2024-04-29

URL: CVE-2024-2756

CVSS 3 Score Details (6.5)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: Required
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: High
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: GHSA-wpj3-hf5j-x4v4

Release Date: 2024-03-21

Fix Resolution: php-8.1.28,php-8.2.18,php-8.3.6


Step up your Open Source Security Game with Mend here

Metadata

Metadata

Assignees

No one assigned

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions