CVE-2024-11234

Updated: 2025-11-10 00:53:48.107457

Description:

In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, when using streams with configured proxy and "request_fulluri" option, the URI is not properly sanitized which can lead to HTTP request smuggling and allow the attacker to use the proxy to perform arbitrary HTTP requests originating from the server, thus potentially gaining access to resources not normally available to the external user.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0.0
CVSS Version 3.x HIGH 7.2

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU php 8.0.30 7.2 HIGH Released CLSA-2025:1737465408 2025-01-22 01:34:46
CentOS 6 ELS php 5.3.3 7.2 HIGH Released CLSA-2024:1734039943 2024-12-25 23:22:35
CentOS 7 ELS php 5.4.16 7.2 HIGH Released CLSA-2024:1733158948 2024-12-12 11:56:16
CentOS 8.4 ELS php 7.4.6 7.2 HIGH Released CLSA-2024:1734006823 2024-12-12 11:56:15
CentOS 8.5 ELS php 7.4.19 7.2 HIGH Released CLSA-2024:1734368826 2024-12-16 13:22:52
CentOS Stream 8 ELS php 7.2.24 7.2 HIGH Released CLSA-2024:1735046232 2024-12-24 22:09:10
CloudLinux 6 ELS php 5.3.3 7.2 HIGH Released CLSA-2024:1734030028 2024-12-25 23:22:37
CloudLinux 7 ELS php 5.4.16 7.2 HIGH Released CLSA-2024:1733158748 2024-12-12 11:56:16
Debian 10 ELS php 7.3 7.2 HIGH Released CLSA-2025:1761577285 2025-10-28 00:35:57
Oracle Linux 6 ELS php 5.3.3 7.2 HIGH Released CLSA-2024:1735132237 2024-12-25 23:22:36
Total: 14