CVE | CVE-2023-0567 |
CVE Title | |
Published Date | 2023-03-01T08:15Z |
Modified Date | 2023-03-01T13:45Z |
Description | In PHP 8.0.X before 8.0.28, 8.1.X before 8.1.16 and 8.2.X before 8.2.3, password_verify() function may accept some invalid Blowfish hashes as valid. If such invalid hash ever ends up in the password database, it may lead to an application allowing any password for this entry as valid. |
References | |
By clicking these links you will leave this website. We do not endorse and will not be held accountable for any activity on external sites. | |
Reference URL | https://github.com/php/php-src/security/advisories/GHSA-7fj2-8x79-rjf4 |
Reference Description | MISC https://github.com/php/php-src/security/advisories/GHSA-7fj2-8x79-rjf4 |
Reference URL | https://bugs.php.net/bug.php?id=81744 |
Reference Description | MISC https://bugs.php.net/bug.php?id=81744 |
Sources | NIST MITRE |
Note
- No CVSS data for this CVE