First published: Mon Jan 04 2021(Updated: )
Fixed bug (FILTER_VALIDATE_URL accepts URLs with invalid userinfo). (CVE-2020-7071)
Credit: security@php.net
Affected Software | Affected Version | How to fix |
---|---|---|
PHP PHP | <8.0.1 | 8.0.1 |
debian/php7.3 | 7.3.31-1~deb10u1 7.3.31-1~deb10u5 | |
debian/php7.4 | 7.4.33-1+deb11u4 | |
PHP PHP | >=7.3.0<7.3.26 | |
PHP PHP | >=7.4.0<7.4.14 | |
PHP PHP | >=8.0.0<8.0.1 | |
Debian Debian Linux | =9.0 | |
Debian Debian Linux | =10.0 | |
NetApp Clustered Data ONTAP |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this bug is CVE-2020-7071.
The title of this bug is 'Fixed bug (FILTER_VALIDATE_URL accepts URLs with invalid userinfo).'
The description of this bug is 'Fixed bug (FILTER_VALIDATE_URL accepts URLs with invalid userinfo).'
PHP PHP version up to 7.3.26 is affected by this bug.
You can fix this bug by updating PHP to version 7.3.26 or higher.