Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2024-5458
Description:In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, due to a code logic error, filtering functions such as filter_var when validating URLs (FILTER_VALIDATE_URL) for certain types of URLs the function will result in invalid user information (username + password part of URLs) being treated as valid user information. This may lead to the downstream code accepting invalid URLs as valid and parsing them incorrectly.
Test IDs: 1.3.6.1.4.1.25623.1.0.856230   1.3.6.1.4.1.25623.1.1.12.2024.6841.1   1.3.6.1.4.1.25623.1.0.856240   1.3.6.1.4.1.25623.1.1.12.2024.6841.2   1.3.6.1.4.1.25623.1.1.4.2024.2038.1   1.3.6.1.4.1.25623.1.1.1.1.2024.5717   1.3.6.1.4.1.25623.1.1.4.2024.2039.1   1.3.6.1.4.1.25623.1.1.1.2.2024.3833   1.3.6.1.4.1.25623.1.1.10.2024.0262  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2024-5458
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PKGTQUOA2NTZ3RXN22CSAUJPIRUYRB4B/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/W45DBOH56NQDRTOM2DN2LNA2FZIMC3PK/
https://github.com/php/php-src/security/advisories/GHSA-w8qr-v226-r27w
https://github.com/php/php-src/security/advisories/GHSA-w8qr-v226-r27w
https://lists.debian.org/debian-lts-announce/2024/06/msg00009.html
http://www.openwall.com/lists/oss-security/2024/06/07/1




© 1998-2025 E-Soft Inc. All rights reserved.