Lucene search

K
ubuntucveUbuntu.comUB:CVE-2024-2756
HistoryApr 16, 2024 - 12:00 a.m.

CVE-2024-2756

2024-04-1600:00:00
ubuntu.com
ubuntu.com
6
partial fix
cookie bypass
pear
xenial
unix

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

8.3 High

AI Score

Confidence

High

0.006 Low

EPSS

Percentile

79.3%

Due to an incomplete fix to CVE-2022-31629
https://github.com/advisories/GHSA-c43m-486j-j32p , network and same-site
attackers can set a standard insecure cookie in the victim’s browser which
is treated as a __Host- or __Secure- cookie by PHP applications.

Notes

Author Note
leosilva version in noble is not affected see (LP: #2061147)
OSVersionArchitecturePackageVersionFilename
ubuntu14.04noarchphp5< anyUNKNOWN
ubuntu16.04noarchphp7.0< 7.0.33-0ubuntu0.16.04.16+esm9UNKNOWN
ubuntu18.04noarchphp7.2< 7.2.24-0ubuntu0.18.04.17+esm3UNKNOWN
ubuntu20.04noarchphp7.4< 7.4.3-4ubuntu2.22UNKNOWN
ubuntu22.04noarchphp8.1< 8.1.2-1ubuntu2.17UNKNOWN
ubuntu23.10noarchphp8.2< 8.2.10-2ubuntu2.1UNKNOWN
ubuntu24.04noarchphp8.3< 8.3.6-0maysync1UNKNOWN

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

8.3 High

AI Score

Confidence

High

0.006 Low

EPSS

Percentile

79.3%