Filter bypass in filter_var (FILTER_VALIDATE_URL)
Published Jun 9, 2024
5.3
MEDIUMCVSS 3.1
EPSS 12.12%
Description
In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, due to a code logic error, filtering functions such as filter_var when validating URLs (FILTER_VALIDATE_URL) for certain types of URLs the function will result in invalid user information (username + password part of URLs) being treated as valid user information. This may lead to the downstream code accepting invalid URLs as valid and parsing them incorrectly.
Affected products
-
Affected
- ≥ 8.1.*, < 8.1.29
- ≥ 8.2.*, < 8.2.20
- ≥ 8.3.*, < 8.3.8
Configuration 1
Configuration 2
- 40
-
Affected
- 40
-
Affected
- ≥ 7.3.27, ≤ 7.3.33
- ≥ 7.4.15, ≤ 7.4.33
- ≥ 8.0.2, ≤ 8.0.30
- ≥ 8.1.0, < 8.1.29
- ≥ 8.2.0, < 8.2.20
- ≥ 8.3.0, < 8.3.8
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Fedora Project | Fedora | unknown | Affected
|
| PHP | PHP | affected | Affected
|
Red Hat Enterprise Linux 8
php:7.4-8100020241113075828.f7998665
Fixed · RHSA-2024:10952
Red Hat Enterprise Linux 8
php:8.2-8100020241112130045.f7998665
Fixed · RHSA-2024:10951
Red Hat Enterprise Linux 9
php-0:8.0.30-2.el9
Fixed · RHSA-2025:7315
Red Hat Enterprise Linux 9
php:8.1-9050020241112144108.9
Fixed · RHSA-2024:10950
Red Hat Enterprise Linux 9
php:8.2-9050020241112094217.9
Fixed · RHSA-2024:10949
Red Hat Enterprise Linux 10
php
Not affected
Red Hat Enterprise Linux 6
php
Out of support scope
Red Hat Enterprise Linux 7
php
Out of support scope
Red Hat Enterprise Linux 8
php:8.0/php
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | php:7.4-8100020241113075828.f7998665 | Fixed | RHSA-2024:10952 |
| Red Hat Enterprise Linux 8 | php:8.2-8100020241112130045.f7998665 | Fixed | RHSA-2024:10951 |
| Red Hat Enterprise Linux 9 | php-0:8.0.30-2.el9 | Fixed | RHSA-2025:7315 |
| Red Hat Enterprise Linux 9 | php:8.1-9050020241112144108.9 | Fixed | RHSA-2024:10950 |
| Red Hat Enterprise Linux 9 | php:8.2-9050020241112094217.9 | Fixed | RHSA-2024:10949 |
| Red Hat Enterprise Linux 10 | php | Not affected | n/a |
| Red Hat Enterprise Linux 6 | php | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | php | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | php:8.0/php | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This flaw in PHP's filter_var function with FILTER_VALIDATE_URL constitutes a moderate severity issue because, while it allows URLs with invalid user information to be treated as valid, it does not directly facilitate immediate security breaches or exploits on its own. The impact is limited to cases where applications rely solely on this function for URL validation without additional checks, potentially leading to improper handling of user credentials. However, the flaw does not compromise the overall integrity of the PHP interpreter, nor does it inherently lead to data corruption or system crashes. Its exploitation requires specific conditions and contexts, making it less critical than high-severity vulnerabilities that enable direct remote code execution or privilege escalation.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (12)
- http://www.openwall.com/lists/oss-security/2024/06/07/1 Mailing ListThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2024-5458 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2291252 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-46674 Advisory
- https://github.com/php/php-src/security/advisories/GHSA-w8qr-v226-r27w ExploitVendor Advisory
- https://lists.debian.org/debian-lts-announce/2024/06/msg00009.html
- https://lists.debian.org/debian-lts-announce/2024/10/msg00011.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PKGTQUOA2NTZ3RXN22CSAUJPIRUYRB4B/ Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/W45DBOH56NQDRTOM2DN2LNA2FZIMC3PK/
- https://nvd.nist.gov/vuln/detail/CVE-2024-5458
- https://security.netapp.com/advisory/ntap-20240726-0001/
- https://www.cve.org/CVERecord?id=CVE-2024-5458
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
GitHub
No data