Multipart-file uploads call variables to be improperly registered in the global scope. In cases where variables are not declared explicitly before being used this can lead to unexpected behavior. This affects all supported versions of HHVM prior to the patch (3.25.1, 3.24.5, and 3.21.9 and below).
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-18094 | Multipart-file uploads call variables to be improperly registered in the global scope. In cases where variables are not declared explicitly before being used this can lead to unexpected behavior. This affects all supported versions of HHVM prior to the patch (3.25.1, 3.24.5, and 3.21.9 and below). |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 06 May 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: facebook
Published:
Updated: 2025-05-06T16:48:40.461Z
Reserved: 2018-01-26T00:00:00.000Z
Link: CVE-2018-6334
Updated: 2024-08-05T06:01:48.426Z
Status : Modified
Published: 2018-12-31T19:29:00.323
Modified: 2025-05-06T17:15:50.730
Link: CVE-2018-6334
No data.
OpenCVE Enrichment
No data.
EUVD