Lucene search

K
cvelistPhpCVELIST:CVE-2022-31629
HistorySep 28, 2022 - 10:25 p.m.

CVE-2022-31629 $_COOKIE names string replacement (. -> _): cookie integrity vulnerabilities

2022-09-2822:25:10
CWE-20
php
www.cve.org
12
cve-2022-31629
cookie integrity
php
network attackers

AI Score

7.4

Confidence

High

EPSS

0.006

Percentile

79.3%

In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the vulnerability enables network and same-site attackers to set a standard insecure cookie in the victim’s browser which is treated as a __Host- or __Secure- cookie by PHP applications.

CNA Affected

[
  {
    "vendor": "PHP Group",
    "product": "PHP",
    "versions": [
      {
        "version": "7.4.X",
        "status": "affected",
        "lessThan": "7.4.31",
        "versionType": "custom"
      },
      {
        "version": "8.0.X",
        "status": "affected",
        "lessThan": "8.0.24",
        "versionType": "custom"
      },
      {
        "version": "8.1.X",
        "status": "affected",
        "lessThan": "8.1.11",
        "versionType": "custom"
      }
    ]
  }
]

References