Release Date: | 2024-10-07 |
In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, HTTP_REDIRECT_STATUS variable is used to check whether or not CGI binary is being run by the HTTP server. However, in certain scenarios, the content of this variable can be controlled by the request submitter via HTTP headers, which can lead to cgi.force_redirect option not being correctly applied. In certain configurations this may lead to arbitrary file inclusion in PHP.
See more information about CVE-2024-8927 from MITRE CVE dictionary and NIST NVD
NOTE: The following CVSS metrics and score provided are preliminary and subject to review.
Base Score: | 7.5 |
Vector String: | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Version: | 3.1 |
Attack Vector: | Network |
Attack Complexity: | Low |
Privileges Required: | None |
User Interaction: | None |
Scope: | Unchanged |
Confidentiality: | High |
Integrity: | None |
Availability: | None |
Platform | Errata | Release Date |
Oracle Linux version 8 (libzip) | ELSA-2024-10951 | 2024-12-11 |
Oracle Linux version 8 (libzip) | ELSA-2024-10952 | 2024-12-12 |
Oracle Linux version 8 (php) | ELSA-2024-10951 | 2024-12-11 |
Oracle Linux version 8 (php) | ELSA-2024-10952 | 2024-12-12 |
Oracle Linux version 8 (php-pear) | ELSA-2024-10951 | 2024-12-11 |
Oracle Linux version 8 (php-pear) | ELSA-2024-10952 | 2024-12-12 |
Oracle Linux version 8 (php-pecl-apcu) | ELSA-2024-10951 | 2024-12-11 |
Oracle Linux version 8 (php-pecl-apcu) | ELSA-2024-10952 | 2024-12-12 |
Oracle Linux version 8 (php-pecl-rrd) | ELSA-2024-10951 | 2024-12-11 |
Oracle Linux version 8 (php-pecl-rrd) | ELSA-2024-10952 | 2024-12-12 |
Oracle Linux version 8 (php-pecl-xdebug) | ELSA-2024-10952 | 2024-12-12 |
Oracle Linux version 8 (php-pecl-xdebug3) | ELSA-2024-10951 | 2024-12-11 |
Oracle Linux version 8 (php-pecl-zip) | ELSA-2024-10951 | 2024-12-11 |
Oracle Linux version 8 (php-pecl-zip) | ELSA-2024-10952 | 2024-12-12 |
Oracle Linux version 9 (php) | ELSA-2024-10949 | 2024-12-11 |
Oracle Linux version 9 (php) | ELSA-2024-10950 | 2024-12-12 |
Oracle Linux version 9 (php-pecl-apcu) | ELSA-2024-10949 | 2024-12-11 |
Oracle Linux version 9 (php-pecl-apcu) | ELSA-2024-10950 | 2024-12-12 |
Oracle Linux version 9 (php-pecl-rrd) | ELSA-2024-10949 | 2024-12-11 |
Oracle Linux version 9 (php-pecl-rrd) | ELSA-2024-10950 | 2024-12-12 |
Oracle Linux version 9 (php-pecl-xdebug3) | ELSA-2024-10949 | 2024-12-11 |
Oracle Linux version 9 (php-pecl-xdebug3) | ELSA-2024-10950 | 2024-12-12 |
Oracle Linux version 9 (php-pecl-zip) | ELSA-2024-10949 | 2024-12-11 |
Oracle Linux version 9 (php-pecl-zip) | ELSA-2024-10950 | 2024-12-12 |
This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections: