CVE-2020-7071

Updated: 2024-11-24 03:31:55.586964

Description:

In PHP versions 7.3.x below 7.3.26, 7.4.x below 7.4.14 and 8.0.0, when validating URL with functions like filter_var($url, FILTER_VALIDATE_URL), PHP will accept an URL with invalid password as valid URL. This may lead to functions that rely on URL being valid to mis-parse the URL and produce wrong data as components of the URL.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x MEDIUM 5
CVSS Version 3.x MEDIUM 5.3

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

Debian 10 php 8.2 5.3 MEDIUM Ignored 2025-05-29 03:54:40
Debian 10 php 8.1 5.3 MEDIUM Ignored 2025-05-29 03:54:40
Debian 10 php 8.0 5.3 MEDIUM Ignored 2025-05-29 03:54:40
Debian 10 php 7.4 5.3 MEDIUM Ignored 2025-05-29 03:54:42
Debian 10 php 7.2 5.3 MEDIUM Ignored 2025-05-29 03:54:42
Debian 10 php 7.1 5.3 MEDIUM Released CLSA-2025:1747428419 2025-05-18 04:56:29
Debian 10 php 7.3 5.3 MEDIUM Ignored 2025-05-29 03:54:42
Debian 10 php 5.6 5.3 MEDIUM Already Fixed 2025-05-01 03:51:35
Debian 10 php 7.0 5.3 MEDIUM Already Fixed 2025-05-02 03:52:15
Debian 11 php 8.1 5.3 MEDIUM Ignored 2025-05-29 03:54:40
Total: 124