CVE-2024-8929

MEDIUM

PHP 8.1.0-8.1.30 - Out-of-bounds Read via MySQL Client Heap Disclosure

Title source: llm
STIX 2.1

Description

In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, a hostile MySQL server can cause the client to disclose the content of its heap containing data from other SQL requests and possible other data belonging to different users of the same server.

Scores

CVSS v3 5.8
EPSS 0.0229
EPSS Percentile 80.9%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-125 CWE-200
Status published
Products (1)
php/php 8.1.0 - 8.1.31
Published Nov 22, 2024
Tracked Since Feb 18, 2026