Description
In PHP versions 7.2.x below 7.2.34, 7.3.x below 7.3.23 and 7.4.x below 7.4.11, when PHP is processing incoming HTTP cookie values, the cookie names are url-decoded. This may lead to cookies with prefixes like __Host confused with cookies that decode to such prefix, thus leading to an attacker being able to forge cookie which is supposed to be secure. See also CVE-2020-8184 for more information.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2397-1 | php7.0 security update |
Debian DSA |
DSA-4856-1 | php7.3 security update |
Ubuntu USN |
USN-4583-1 | PHP vulnerabilities |
Ubuntu USN |
USN-4583-2 | PHP vulnerabilities |
References
History
No history.
Subscriptions
Canonical
Subscribe
Ubuntu Linux
Subscribe
Debian
Subscribe
Debian Linux
Subscribe
Fedoraproject
Subscribe
Fedora
Subscribe
Netapp
Subscribe
Clustered Data Ontap
Subscribe
Opensuse
Subscribe
Leap
Subscribe
Php
Subscribe
Php
Subscribe
Redhat
Subscribe
Enterprise Linux
Subscribe
Rhel Software Collections
Subscribe
Tenable
Subscribe
Tenable.sc
Subscribe
Status: PUBLISHED
Assigner: php
Published:
Updated: 2024-09-16T16:28:36.773Z
Reserved: 2020-01-15T00:00:00.000Z
Link: CVE-2020-7070
No data.
Status : Modified
Published: 2020-10-02T15:15:12.747
Modified: 2024-11-21T05:36:37.007
Link: CVE-2020-7070
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
Ubuntu USN