CVE-2024-3096
Public on 2024-04-15
Modified on 2024-04-15
Description
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to an error in within the password_verify() function, which can erroneously return true. A remote attacker can bypass implemented authentication based on the vulnerable function and gain unauthorized access to the web application.
The vulnerability exists due to an error in within the password_verify() function, which can erroneously return true. A remote attacker can bypass implemented authentication based on the vulnerable function and gain unauthorized access to the web application.
Severity
See what this means
CVSS v3 Base Score
See breakdown
Affected Packages
Platform | Package | Release Date | Advisory | Status |
---|---|---|---|---|
Amazon Linux 2 - Core | php | Not Affected | ||
Amazon Linux 2 - Php8.1 Extra | php | 2024-06-24 | ALAS2PHP8.1-2024-005 | Fixed |
Amazon Linux 2 - Php8.2 Extra | php | 2024-05-30 | ALAS2PHP8.2-2024-004 | Fixed |
Amazon Linux 1 | php56 | Pending Fix | ||
Amazon Linux 2023 | php8.1 | 2024-05-13 | ALAS2023-2024-612 | Fixed |
Amazon Linux 2023 | php8.2 | 2024-05-28 | ALAS2023-2024-624 | Fixed |
CVSS Scores
Score Type | Score | Vector | |
---|---|---|---|
Amazon Linux | CVSSv3 | 8.3 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L |
NVD | CVSSv3 | 6.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N |