CVE-2024-11234

MEDIUM

PHP 8.1.0-8.1.30 - HTTP Request Smuggling via Proxy Stream URI Sanitization Bypass

Title source: llm
STIX 2.1

Description

In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, when using streams with configured proxy and "request_fulluri" option, the URI is not properly sanitized which can lead to HTTP request smuggling and allow the attacker to use the proxy to perform arbitrary HTTP requests originating from the server, thus potentially gaining access to resources not normally available to the external user.

Scores

CVSS v3 4.8
EPSS 0.0115
EPSS Percentile 78.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-74 CWE-20
Status published
Products (1)
php/php 8.1.0 - 8.1.31
Published Nov 24, 2024
Tracked Since Feb 18, 2026