CVE-2023-0567: password_verify() always returns true for some invalid hashes

Published Feb 14, 2023
·
Updated

CVE-2023-0567[0]: PHP: Passwordverify() always return true with some hash

[0] https://security-tracker.debian.org/tracker/CVE-2023-0567 https://www.cve.org/CVERecord?id=CVE-2023-0567 https://github.com/php/php-src/security/advisories/GHSA-7fj2-8x79-rjf4

Other sources

Fixed bug (Passwordverify() always return true with some hash). (CVE-2023-0567)

PHP

In PHP 8.0.X before 8.0.28, 8.1.X before 8.1.16 and 8.2.X before 8.2.3, passwordverify() function may accept some invalid Blowfish hashes as valid. If such invalid hash ever ends up in the password database, it may lead to an application allowing any password for this entry as valid.

Launchpad

passwordverify() always returns true for some invalid hashes

Microsoft

Affected Software

6 affected componentsFixes available
PHP PHP>=8.0.0<8.0.28
PHP PHP>=8.1.0<8.1.16
PHP PHP>=8.2.0<8.2.3
PHP PHP<8.2.3
8.2.3
Microsoft cbl2 php 8.1.16-1<8.1.16-1
8.1.16-1
debian/php8.2
8.2.32-1~deb12u18.2.33-1~deb12u1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade PHP to a version that resolves this vulnerability.

    Fixed in 8.2.3
  2. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 8.1.16-1
  3. Upgrade

    Upgrade debian/php8.2 to a version that resolves this vulnerability.

    Fixed in 8.2.32-1~deb12u1Fixed in 8.2.33-1~deb12u1
  4. Upgrade

    Upgrade PHP to a version that resolves this vulnerability.

    Fixed in 8.0.28
  5. Upgrade

    Upgrade PHP to a version that resolves this vulnerability.

    Fixed in 8.1.16
  6. Compensating control

    If an invalid Blowfish hash could be present in the password database, review/validate password hash entries to ensure they are valid, since password_verify() may accept invalid hashes as valid.

Event History

Feb 14, 2023
CVE Published
via PHP·12:00 AM
Feb 16, 2023
CVE Published
via MITRE·06:15 AM
Data Sourced
via MITRE·06:15 AM
DescriptionSeverity
Feb 17, 2023
Data Sourced
via Red Hat·08:34 AM
DescriptionSeverityAffected Software
Mar 1, 2023
Data Sourced
via Microsoft·08:00 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·08:00 AM
Affected Software
Updated
via Microsoft·08:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 AM
DescriptionSeverityWeaknessAffected Software
Jan 12, 2024
Data Sourced
via Launchpad·06:03 PM
Description
Sep 24, 2024
Data Sourced
via Ubuntu·06:42 PM
RemedyDescriptionSeverityAffected Software
Sep 2, 2026
Data Sourced
via Debian·03:09 AM
DescriptionAffected Software

Frequently Asked Questions

1

What is the vulnerability ID for this bug?

The vulnerability ID for this bug is CVE-2023-0567.

2

What is the title of this bug?

The title of this bug is Fixed bug (Password_verify() always return true with some hash).

3

What is the affected software?

The affected software is PHP 8.2.3.

4

How severe is this vulnerability?

The severity of this vulnerability is not mentioned.

5

How can I fix this vulnerability?

The vulnerability can be fixed by updating PHP to version 8.2.3.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203