CVE-2024-8929
Last modified
CVE-2024-8929 is a medium-severity vulnerability rated 5.8/10 on the CVSS scale. In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, a hostile MySQL server can cause the client to disclose the content of its heap containing data from other SQL requests and possible other data belonging to different users of the same server.. EPSS estimates a 2.29% chance of exploitation in the next 30 days.
Description
In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, a hostile MySQL server can cause the client to disclose the content of its heap containing data from other SQL requests and possible other data belonging to different users of the same server.
Metrics
CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Php | Php | >= 8.1.0, < 8.1.31 |
| Php | Php | >= 8.2.0, < 8.2.26 |
| Php | Php | >= 8.3.0, < 8.3.14 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2024-8929?
How severe is CVE-2024-8929?
How do I fix CVE-2024-8929?
Are you affected by CVE-2024-8929?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
