In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, when using PHP-FPM SAPI and it is configured to catch workers output through catch_workers_output = yes, it may be possible to pollute the final log or remove up to 4 characters from the log messages by manipulating log message content. Additionally, if PHP-FPM is configured to use syslog output, it may be possible to further remove log data using the same vulnerability.
Metrics
Affected Vendors & Products
References
History
Wed, 16 Oct 2024 18:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Php-fpm
Php-fpm php-fpm |
|
Weaknesses | NVD-CWE-Other | |
CPEs | cpe:2.3:a:php-fpm:php-fpm:*:*:*:*:*:*:*:* | |
Vendors & Products |
Php-fpm
Php-fpm php-fpm |
Wed, 09 Oct 2024 13:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
| |
Metrics |
threat_severity
|
threat_severity
|
Tue, 08 Oct 2024 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Php
Php php |
|
CPEs | cpe:2.3:a:php:php:*:*:*:*:*:*:*:* | |
Vendors & Products |
Php
Php php |
|
Metrics |
ssvc
|
Tue, 08 Oct 2024 04:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, when using PHP-FPM SAPI and it is configured to catch workers output through catch_workers_output = yes, it may be possible to pollute the final log or remove up to 4 characters from the log messages by manipulating log message content. Additionally, if PHP-FPM is configured to use syslog output, it may be possible to further remove log data using the same vulnerability. | |
Title | PHP-FPM logs from children may be altered | |
Weaknesses | CWE-117 CWE-158 |
|
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: php
Published: 2024-10-08T04:07:33.452Z
Updated: 2024-10-08T13:52:08.340Z
Reserved: 2024-09-20T00:15:42.321Z
Link: CVE-2024-9026
Vulnrichment
Updated: 2024-10-08T12:49:08.252Z
NVD
Status : Analyzed
Published: 2024-10-08T04:15:11.060
Modified: 2024-10-16T18:30:37.133
Link: CVE-2024-9026
Redhat