CVE Vulnerabilities

CVE-2024-8925

Published: Oct 08, 2024 | Modified: Oct 16, 2024
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
5.3 MODERATE
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N
Ubuntu
MEDIUM

In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, erroneous parsing of multipart form data contained in an HTTP POST request could lead to legitimate data not being processed. This could lead to malicious attacker able to control part of the submitted data being able to exclude portion of other data, potentially leading to erroneous application behavior.

Affected Software

Name Vendor Start Version End Version
Php-fpm Php-fpm 8.1.0 (including) 8.1.30 (excluding)
Php-fpm Php-fpm 8.2.0 (including) 8.2.24 (excluding)
Php-fpm Php-fpm 8.3.0 (including) 8.3.12 (excluding)
Php7.0 Ubuntu esm-infra/xenial *
Php7.2 Ubuntu esm-infra/bionic *
Php7.4 Ubuntu focal *
Php8.1 Ubuntu jammy *
Php8.1 Ubuntu upstream *
Php8.3 Ubuntu devel *
Php8.3 Ubuntu noble *
Php8.3 Ubuntu oracular *
Php8.3 Ubuntu upstream *

References