CVE-2024-11234
Publication date 24 November 2024
Last updated 13 December 2024
Ubuntu priority
Cvss 3 Severity Score
In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, when using streams with configured proxy and "request_fulluri" option, the URI is not properly sanitized which can lead to HTTP request smuggling and allow the attacker to use the proxy to perform arbitrary HTTP requests originating from the server, thus potentially gaining access to resources not normally available to the external user.
Status
Package | Ubuntu Release | Status |
---|---|---|
php5 | 24.10 oracular | Not in release |
24.04 LTS noble | Not in release | |
22.04 LTS jammy | Not in release | |
20.04 LTS focal | Not in release | |
14.04 LTS trusty | Ignored end of ESM support, was needs-triage | |
php7.0 | 24.10 oracular | Not in release |
24.04 LTS noble | Not in release | |
22.04 LTS jammy | Not in release | |
20.04 LTS focal | Not in release | |
16.04 LTS xenial |
Needs evaluation
|
|
php7.2 | 24.10 oracular | Not in release |
24.04 LTS noble | Not in release | |
22.04 LTS jammy | Not in release | |
20.04 LTS focal | Not in release | |
18.04 LTS bionic |
Needs evaluation
|
|
php7.4 | 24.10 oracular | Not in release |
24.04 LTS noble | Not in release | |
22.04 LTS jammy | Not in release | |
20.04 LTS focal |
Fixed 7.4.3-4ubuntu2.26
|
|
php8.1 | 24.10 oracular | Not in release |
24.04 LTS noble | Not in release | |
22.04 LTS jammy |
Fixed 8.1.2-1ubuntu2.20
|
|
20.04 LTS focal | Not in release | |
php8.3 | 24.10 oracular |
Fixed 8.3.11-0ubuntu0.24.10.4
|
24.04 LTS noble |
Fixed 8.3.6-0ubuntu0.24.04.3
|
|
22.04 LTS jammy | Not in release | |
20.04 LTS focal | Not in release |
Notes
Severity score breakdown
Parameter | Value |
---|---|
Base score | 7.2 · High |
Attack vector | Network |
Attack complexity | Low |
Privileges required | None |
User interaction | None |
Scope | Changed |
Confidentiality | Low |
Integrity impact | Low |
Availability impact | None |
Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N |
References
Related Ubuntu Security Notices (USN)
- USN-7157-1
- PHP vulnerabilities
- 13 December 2024