CVE-2024-8929

MEDIUM

Php < 8.1.31 - Information Disclosure

Title source: rule
STIX 2.1

Description

In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, a hostile MySQL server can cause the client to disclose the content of its heap containing data from other SQL requests and possible other data belonging to different users of the same server.

Scores

CVSS v3 5.8
EPSS 0.0066
EPSS Percentile 71.2%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-125 CWE-200
Status published
Products (1)
php/php 8.1.0 - 8.1.31
Published Nov 22, 2024
Tracked Since Feb 18, 2026