CVE-2024-8927

CVE Details

Release Date:2024-10-07

Description


In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, HTTP_REDIRECT_STATUS variable is used to check whether or not CGI binary is being run by the HTTP server. However, in certain scenarios, the content of this variable can be controlled by the request submitter via HTTP headers, which can lead to cgi.force_redirect option not being correctly applied. In certain configurations this may lead to arbitrary file inclusion in PHP.

See more information about CVE-2024-8927 from MITRE CVE dictionary and NIST NVD


NOTE: The following CVSS metrics and score provided are preliminary and subject to review.


CVSS v3 metrics

Base Score: 7.5
Vector String: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Version: 3.1
Attack Vector: Network
Attack Complexity: Low
Privileges Required: None
User Interaction: None
Scope: Unchanged
Confidentiality: High
Integrity: None
Availability: None

Errata information


PlatformErrataRelease Date
Oracle Linux version 8 (libzip)ELSA-2024-109512024-12-11
Oracle Linux version 8 (libzip)ELSA-2024-109522024-12-12
Oracle Linux version 8 (php)ELSA-2024-109512024-12-11
Oracle Linux version 8 (php)ELSA-2024-109522024-12-12
Oracle Linux version 8 (php-pear)ELSA-2024-109512024-12-11
Oracle Linux version 8 (php-pear)ELSA-2024-109522024-12-12
Oracle Linux version 8 (php-pecl-apcu)ELSA-2024-109512024-12-11
Oracle Linux version 8 (php-pecl-apcu)ELSA-2024-109522024-12-12
Oracle Linux version 8 (php-pecl-rrd)ELSA-2024-109512024-12-11
Oracle Linux version 8 (php-pecl-rrd)ELSA-2024-109522024-12-12
Oracle Linux version 8 (php-pecl-xdebug)ELSA-2024-109522024-12-12
Oracle Linux version 8 (php-pecl-xdebug3)ELSA-2024-109512024-12-11
Oracle Linux version 8 (php-pecl-zip)ELSA-2024-109512024-12-11
Oracle Linux version 8 (php-pecl-zip)ELSA-2024-109522024-12-12
Oracle Linux version 9 (php)ELSA-2024-109492024-12-11
Oracle Linux version 9 (php)ELSA-2024-109502024-12-12
Oracle Linux version 9 (php-pecl-apcu)ELSA-2024-109492024-12-11
Oracle Linux version 9 (php-pecl-apcu)ELSA-2024-109502024-12-12
Oracle Linux version 9 (php-pecl-rrd)ELSA-2024-109492024-12-11
Oracle Linux version 9 (php-pecl-rrd)ELSA-2024-109502024-12-12
Oracle Linux version 9 (php-pecl-xdebug3)ELSA-2024-109492024-12-11
Oracle Linux version 9 (php-pecl-xdebug3)ELSA-2024-109502024-12-12
Oracle Linux version 9 (php-pecl-zip)ELSA-2024-109492024-12-11
Oracle Linux version 9 (php-pecl-zip)ELSA-2024-109502024-12-12


This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections:

software.hardware.complete