PHP parses encoded cookie names so malicious `__Host-` cookies can be sent
Vulnerability Description
In PHP versions 7.2.x below 7.2.34, 7.3.x below 7.3.23 and 7.4.x below 7.4.11, when PHP is processing incoming HTTP cookie values, the cookie names are url-decoded. This may lead to cookies with prefixes like __Host confused with cookies that decode to such prefix, thus leading to an attacker being able to forge cookie which is supposed to be secure. See also CVE-2020-8184 for more information.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-7070
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Reported by fletchto99 at gmail dot com
References
- https://hackerone.com/reports/895727
- https://bugs.php.net/bug.php?id=79699
- http://cve.circl.lu/cve/CVE-2020-8184
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RRU57N3OSYZPOMFWPRDNVH7EMYOTSZ66/
- https://lists.debian.org/debian-lts-announce/2020/10/msg00008.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7EVDN7D3IB4EAI4D3ZOM2OJKQ5SD7K4E/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/P2J3ZZDHCSX65T5QWV4AHBN7MOJXBEKG/
- http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00045.html
- https://usn.ubuntu.com/4583-1/
- http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00067.html
- https://security.gentoo.org/glsa/202012-16
- https://www.debian.org/security/2021/dsa-4856
- https://security.netapp.com/advisory/ntap-20201016-0001/
- https://www.oracle.com/security-alerts/cpuoct2021.html
- https://www.tenable.com/security/tns-2021-14
More from PHP Group
View All →Affected Vendor
PHP Group
View all reports →