CVE-2024-5458

Updated: 2025-11-10 02:27:17.783672

Description:

In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, due to a code logic error, filtering functions such as filter_var when validating URLs (FILTER_VALIDATE_URL) for certain types of URLs the function will result in invalid user information (username + password part of URLs) being treated as valid user information. This may lead to the downstream code accepting invalid URLs as valid and parsing them incorrectly.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0.0
CVSS Version 3.x MEDIUM 5.3

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

Oracle Linux 7 ELS php 5.4.16 5.3 MEDIUM Ignored 2024-12-03 12:09:52 Ignored due to low severity
RHEL 7 ELS php 5.4.16 5.3 MEDIUM Ignored 2025-05-13 06:31:26 Ignored due to low severity
Ubuntu 16.04 ELS php 7.0.33 5.3 MEDIUM Released CLSA-2024:1718789388 2024-06-19 10:09:27
Ubuntu 18.04 ELS php 7.2.24-0 5.3 MEDIUM Released CLSA-2024:1718789955 2024-06-19 10:09:30
Total: 14