• Tenable
  • CVEs
  • Settings
    Links
    Tenable.io Tenable Community & Support Tenable University
    Severity
    Theme
  • Tenable
  • Links
  • Tenable.io
  • Tenable Community & Support
  • Tenable University
  • Settings
  • Severity
  • Theme
  • Newest
  • Updated
  • Search
  • Newest
  • Updated
  • Search
  1. CVEs
  2. CVE-2022-31629
  1. CVEs

CVE-2022-31629

medium
  • Information
  • CPEs
  • Plugins

Description

In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the vulnerability enables network and same-site attackers to set a standard insecure cookie in the victim's browser which is treated as a `__Host-` or `__Secure-` cookie by PHP applications.

References

https://bugs.php.net/bug.php?id=81727

https://lists.fedoraproject.org/archives/list/[email protected]/message/XNIEABBH5XCXLFWWZYIDE457SPEDZTXV/

https://lists.fedoraproject.org/archives/list/[email protected]/message/VI3E6A3ZTH2RP7OMLJHSVFIEQBIFM6RF/

https://www.debian.org/security/2022/dsa-5277

https://lists.fedoraproject.org/archives/list/[email protected]/message/2L5SUVYGAKSWODUQPZFBUB3AL6E6CSEV/

https://security.gentoo.org/glsa/202211-03

https://security.netapp.com/advisory/ntap-20221209-0001/

https://lists.debian.org/debian-lts-announce/2022/12/msg00030.html

Details

Source: MITRE

Published: 2022-09-28

Updated: 2023-01-20

Type: NVD-CWE-noinfo

  • Tenable.com
  • Community & Support
  • Documentation
  • Education
  • © 2023 Tenable®, Inc. All Rights Reserved
  • Privacy Policy
  • Legal
  • 508 Compliance