CVE-2024-5458
Last modified
CVE-2024-5458 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, due to a code logic error, filtering functions such as filter_var when validating URLs (FILTER_VALIDATE_URL) for certain types of URLs the function will result in invalid user information (username + password part of URLs) being treated as valid user information. This may lead to the downstream code accepting invalid URLs as valid and parsing them incorrectly.. EPSS estimates a 12.12% chance of exploitation in the next 30 days.
Description
In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, due to a code logic error, filtering functions such as filter_var when validating URLs (FILTER_VALIDATE_URL) for certain types of URLs the function will result in invalid user information (username + password part of URLs) being treated as valid user information. This may lead to the downstream code accepting invalid URLs as valid and parsing them incorrectly.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Php | Php | >= 7.3.27, <= 7.3.33 |
| Php | Php | >= 7.4.15, <= 7.4.33 |
| Php | Php | >= 8.0.2, <= 8.0.30 |
| Php | Php | >= 8.1.0, < 8.1.29 |
| Php | Php | >= 8.2.0, < 8.2.20 |
| Php | Php | >= 8.3.0, < 8.3.8 |
| Fedoraproject | Fedora | 40 |
References
- https://www.openwall.com/lists/oss-security/2024/06/07/1Mailing List, Third Party Advisory
- https://github.com/php/php-src/security/advisories/GHSA-w8qr-v226-r27wExploit, Vendor Advisory
- https://www.openwall.com/lists/oss-security/2024/06/07/1Mailing List, Third Party Advisory
- https://github.com/php/php-src/security/advisories/GHSA-w8qr-v226-r27wExploit, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2024-5458?
How severe is CVE-2024-5458?
How do I fix CVE-2024-5458?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-5456The Panda Video plugin for WordPress is vulnerable to Local …8.8
- CVE-2024-54560A logic issue was addressed with improved checks. This issue…5.5
- CVE-2024-54564This issue was addressed through improved state management. …6.5
- CVE-2024-54565The issue was addressed with improved checks. This issue is …6.2
- CVE-2024-54568The issue was addressed with improved memory handling. This …4.3
- CVE-2024-5457The Panda Video plugin for WordPress is vulnerable to Stored…5.4
- CVE-2024-5459The Restaurant Menu and Food Ordering plugin for WordPress i…4.3
- CVE-2024-5460A vulnerability in the default configuration of the Simple N…8.1
- CVE-2024-5461Implementation of the Simple Network Management Protocol (S…8
- CVE-2024-5462If Brocade Fabric OS before Fabric OS 9.2.0 configuration se…7.5
- CVE-2024-5463A vulnerability regarding buffer copy without checking the s…6.5
- CVE-2024-5464Vulnerability of insufficient permission verification in the…3.3
Are you affected by CVE-2024-5458?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
