VDB
BDU%3A2022-02618
BDU%3A2022-02618
PUBLISHED
CVSS 6.800000190734863 MEDIUM
Уязвимость подсистемы sessions интерпретатора языка программирования PHP, позволяющая нарушителю перехватить сессию пользователя
Risk Scores
CVSS 2.0
6.800000190734863
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Novell Inc., Сообщество свободного программного обеспечения, PHP Group | OpenSUSE Leap, Debian GNU/Linux, PHP |
Timeline
- Apr 27, 2022 CVE Published
References
- https://wiki.php.net/rfc/strict_sessions url
- https://bugs.php.net/bug.php?id=60491 url
- http://git.php.net/?p=php-src.git;a=commit;h=25e8fcc88fa20dc9d4c47184471003f436927cde url
- http://git.php.net/?p=php-src.git;a=commit;h=169b78eb79b0e080b67f9798708eb3771c6d0b2f url
- https://www.suse.com/security/cve/CVE-2011-4718 advisory
- https://security-tracker.debian.org/tracker/CVE-2011-4718 advisory