CVE-2022-31629

Updated: 2025-11-10 01:35:27.354636

Description:

In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the vulnerability enables network and same-site attackers to set a standard insecure cookie in the victim's browser which is treated as a `__Host-` or `__Secure-` cookie by PHP applications.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0.0
CVSS Version 3.x MEDIUM 6.5

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU php 8.0.30 6.5 MEDIUM Already Fixed 2025-01-29 01:44:17
CentOS 6 ELS php 5.3.3 6.5 MEDIUM Released CLSA-2024:1715280966 2024-05-29 10:29:47
CentOS 7 ELS php 5.4.16 6.5 MEDIUM Ignored 2024-01-21 08:36:31 Ignored due to low severity
CentOS 8.4 ELS php 7.4.6 6.5 MEDIUM Released CLSA-2023:1686859492 2023-06-15 17:08:36
CentOS 8.5 ELS php 7.4.19 6.5 MEDIUM Released CLSA-2023:1686858853 2023-06-15 17:08:37
CentOS Stream 8 ELS php 7.2.24 6.5 MEDIUM Released CLSA-2024:1735310755 2024-12-28 22:36:54
CloudLinux 6 ELS php 5.3.3 6.5 MEDIUM Released CLSA-2024:1715281170 2024-06-03 14:38:10
Debian 10 ELS php 7.3 6.5 MEDIUM Ignored 2025-10-11 00:21:05 Ignored due to low severity
Oracle Linux 6 ELS php 5.3.3 6.5 MEDIUM Released CLSA-2024:1715281321 2024-05-09 17:36:28
Ubuntu 16.04 ELS php 7.0.33 6.5 MEDIUM Released CLSA-2023:1679944242 2023-03-27 17:07:03
Total: 11