In PHP versions 7.3.x below 7.3.29, 7.4.x below 7.4.21 and 8.0.x below 8.0.8, when using URL validation functionality via filter_var() function with FILTER_VALIDATE_URL parameter, an URL with invalid password field can be accepted as valid. This can lead to the code incorrectly parsing the URL and potentially leading to other security implications - like contacting a wrong server or making a wrong access decision.
2021-10-04T04:15:08.210
2024-11-21T05:48:52.327
Modified
CVSSv3.1: 4.3 (MEDIUM)
AV:N/AC:L/Au:N/C:N/I:P/A:N
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | php | php | < 7.3.29 | Yes |
Application | php | php | < 7.4.21 | Yes |
Application | php | php | < 8.0.8 | Yes |
Application | netapp | clustered_data_ontap | - | Yes |
Application | oracle | sd-wan_aware | 8.2 | Yes |