CVE-2024-2756

Updated: 2025-02-13 22:58:22.226644

Description:

Due to an incomplete fix to CVE-2022-31629 https://github.com/advisories/GHSA-c43m-486j-j32p , network and same-site attackers can set a standard insecure cookie in the victim's browser which is treated as a __Host- or __Secure- cookie by PHP applications.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x NONE 0
CVSS Version 3.x MEDIUM 6.5

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

EL 6 php 5.6 6.5 MEDIUM Released CLSA-2024:1716475196 2024-05-23 11:17:44
EL 6 php 7.2 6.5 MEDIUM Released CLSA-2024:1716479247 2024-05-23 14:16:38
EL 6 php 5.2 6.5 MEDIUM Released CLSA-2024:1716979051 2024-05-29 10:04:12
EL 6 php 5.4 6.5 MEDIUM Released CLSA-2024:1716471773 2024-05-23 10:04:45
EL 6 php 7.4 6.5 MEDIUM Released CLSA-2024:1716485147 2024-05-23 14:16:31
EL 6 php 5.5 6.5 MEDIUM Released CLSA-2024:1716472351 2024-05-23 10:04:39
EL 6 php 7.0 6.5 MEDIUM Released CLSA-2024:1716475954 2024-05-23 11:17:42
EL 6 php 7.1 6.5 MEDIUM Released CLSA-2024:1716476734 2024-05-23 11:17:41
EL 6 php 5.3 6.5 MEDIUM Released CLSA-2024:1716979432 2024-05-29 10:04:11
EL 6 php 7.3 6.5 MEDIUM Released CLSA-2024:1716484553 2024-05-23 14:16:38
Total: 83