5.3

CVE-2020-7070

Exploit

PHP parses encoded cookie names so malicious `__Host-` cookies can be sent

In PHP versions 7.2.x below 7.2.34, 7.3.x below 7.3.23 and 7.4.x below 7.4.11, when PHP is processing incoming HTTP cookie values, the cookie names are url-decoded. This may lead to cookies with prefixes like __Host confused with cookies that decode to such prefix, thus leading to an attacker being able to forge cookie which is supposed to be secure. See also CVE-2020-8184 for more information.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Php ≫ Php Version >= 7.2.0 < 7.2.34
Php ≫ Php Version >= 7.3.0 < 7.3.23
Php ≫ Php Version >= 7.4.0 < 7.4.11
Fedoraproject ≫ Fedora Version 31
Fedoraproject ≫ Fedora Version 32
Fedoraproject ≫ Fedora Version 33
Debian ≫ Debian Linux Version 9.0
Debian ≫ Debian Linux Version 10.0
Opensuse ≫ Leap Version 15.1
Opensuse ≫ Leap Version 15.2
Canonical ≫ Ubuntu Linux Version 12.04 SwEdition -
Canonical ≫ Ubuntu Linux Version 14.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 18.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 20.04 SwEdition lts
Tenable ≫ Tenable.Sc Version < 5.19.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 5.03% 0.912
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:P/A:N
PHP 4.3 2.8 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

CWE-565 Reliance on Cookies without Validation and Integrity Checking

The product relies on the existence or values of cookies when performing security-critical operations, but it does not properly ensure that the setting is valid for the associated user.

https://www.oracle.com/security-alerts/cpuoct2021.html
Third Party Advisory
Not Applicable
https://www.tenable.com/security/tns-2021-14
Third Party Advisory
https://hackerone.com/reports/895727
Third Party Advisory
Exploit
https://www.debian.org/security/2021/dsa-4856
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00045.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00067.html
Third Party Advisory
Mailing List
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7EVDN7D3IB4EAI4D3ZOM2OJKQ5SD7K4E/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/P2J3ZZDHCSX65T5QWV4AHBN7MOJXBEKG/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RRU57N3OSYZPOMFWPRDNVH7EMYOTSZ66/
https://security.gentoo.org/glsa/202012-16
Third Party Advisory
https://security.netapp.com/advisory/ntap-20201016-0001/
Third Party Advisory
https://usn.ubuntu.com/4583-1/
Third Party Advisory
http://cve.circl.lu/cve/CVE-2020-8184
Third Party Advisory
https://bugs.php.net/bug.php?id=79699
Vendor Advisory
Issue Tracking
https://lists.debian.org/debian-lts-announce/2020/10/msg00008.html
Third Party Advisory
Mailing List