Wind River Support Network

HomeDefectsLIN1021-8189
Fixed

LIN1021-8189 : Security Advisory - php - CVE-2024-2756

Created: Apr 11, 2024    Updated: Jun 11, 2024
Resolved Date: Jun 10, 2024
Found In Version: 10.21.20.1
Severity: Standard
Applicable for: Wind River Linux LTS 21
Component/s: Userspace

Description

Due to an incomplete fix to  CVE-2022-31629 https://github.com/advisories/GHSA-c43m-486j-j32p , network and same-site attackers can set a standard insecure cookie in the victim's browser which is treated as a __Host- or __Secure- cookie by PHP applications. 

https://nvd.nist.gov/vuln/detail/CVE-2024-2756

CVEs


Live chat
Online