CVE-2024-5458

Updated: 2025-11-10 02:27:17.783672

Description:

In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, due to a code logic error, filtering functions such as filter_var when validating URLs (FILTER_VALIDATE_URL) for certain types of URLs the function will result in invalid user information (username + password part of URLs) being treated as valid user information. This may lead to the downstream code accepting invalid URLs as valid and parsing them incorrectly.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0.0
CVSS Version 3.x MEDIUM 5.3

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

Debian 10 php 8.0 5.3 MEDIUM Released 2025-05-29 03:53:04
Debian 10 php 5.6 5.3 MEDIUM Already Fixed 2025-05-29 03:53:05
Debian 10 php 7.3 5.3 MEDIUM Released 2025-05-29 03:53:04
Debian 10 php 8.2 5.3 MEDIUM Already Fixed 2025-05-29 03:53:04
Debian 10 php 8.1 5.3 MEDIUM Already Fixed 2025-05-29 03:53:04
Debian 10 php 7.0 5.3 MEDIUM Released 2025-05-29 03:53:05
Debian 10 php 7.1 5.3 MEDIUM Released 2025-05-29 03:53:04
Debian 10 php 7.2 5.3 MEDIUM Released 2025-05-29 03:53:04
Debian 10 php 7.4 5.3 MEDIUM Released 2025-05-29 03:53:04
Debian 11 php 8.1 5.3 MEDIUM Already Fixed 2025-05-29 03:53:03
Total: 146