CVE-2024-11234

Updated: 2025-11-10 00:53:48.107457

Description:

In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, when using streams with configured proxy and "request_fulluri" option, the URI is not properly sanitized which can lead to HTTP request smuggling and allow the attacker to use the proxy to perform arbitrary HTTP requests originating from the server, thus potentially gaining access to resources not normally available to the external user.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0.0
CVSS Version 3.x HIGH 7.2

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

Oracle Linux 7 ELS php 5.4.16 7.2 HIGH Released CLSA-2024:1733429914 2024-12-18 22:57:46
RHEL 7 ELS php 5.4.16 7.2 HIGH Released CLSA-2025:1748639500 2025-06-02 16:07:02
Ubuntu 16.04 ELS php 7.0.33 7.2 HIGH Released CLSA-2024:1734704732 2024-12-20 23:13:47
Ubuntu 18.04 ELS php 7.2.24-0 7.2 HIGH Released CLSA-2024:1735064231 2024-12-24 22:09:11
Total: 14