In PHP 8.0.X before 8.0.28, 8.1.X before 8.1.16 and 8.2.X before 8.2.3, password_verify() function may accept some invalid Blowfish hashes as valid. If such invalid hash ever ends up in the password database, it may lead to an application allowing any password for this entry as valid.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3345-1 | php7.3 security update |
Debian DSA |
DSA-5363-1 | php7.4 security update |
EUVD |
EUVD-2023-12609 | In PHP 8.0.X before 8.0.28, 8.1.X before 8.1.16 and 8.2.X before 8.2.3, password_verify() function may accept some invalid Blowfish hashes as valid. If such invalid hash ever ends up in the password database, it may lead to an application allowing any password for this entry as valid. |
Ubuntu USN |
USN-5902-1 | PHP vulnerabilities |
Ubuntu USN |
USN-6053-1 | PHP vulnerability |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: php
Published:
Updated: 2024-08-02T05:17:50.104Z
Reserved: 2023-01-29T07:45:55.380Z
Link: CVE-2023-0567
Updated: 2024-07-31T20:13:47.480Z
Status : Modified
Published: 2023-03-01T08:15:11.530
Modified: 2024-11-21T07:37:24.913
Link: CVE-2023-0567
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
EUVD
Ubuntu USN