VYPR
High severity7.5NVD Advisory· Published Jun 26, 2019· Updated Jun 17, 2026

CVE-2019-3569

CVE-2019-3569

Description

HHVM, when used with FastCGI, would bind by default to all available interfaces. This behavior could allow a malicious individual unintended direct access to the application, which could result in information disclosure. This issue affects versions 4.3.0, 4.4.0, 4.5.0, 4.6.0, 4.7.0, 4.8.0, versions 3.30.5 and below, and all versions in the 4.0, 4.1, and 4.2 series.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

16
  • Facebook/Hhvm16 versions
    cpe:2.3:a:facebook:hhvm:*:*:*:*:*:*:*:*+ 15 more
    • cpe:2.3:a:facebook:hhvm:*:*:*:*:*:*:*:*range: <=3.30.5
    • cpe:2.3:a:facebook:hhvm:4.0.0:*:*:*:*:*:*:*
    • cpe:2.3:a:facebook:hhvm:4.0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:facebook:hhvm:4.0.2:*:*:*:*:*:*:*
    • cpe:2.3:a:facebook:hhvm:4.0.3:*:*:*:*:*:*:*
    • cpe:2.3:a:facebook:hhvm:4.0.4:*:*:*:*:*:*:*
    • cpe:2.3:a:facebook:hhvm:4.1.0:*:*:*:*:*:*:*
    • cpe:2.3:a:facebook:hhvm:4.2.0:*:*:*:*:*:*:*
    • cpe:2.3:a:facebook:hhvm:4.3.0:*:*:*:*:*:*:*
    • cpe:2.3:a:facebook:hhvm:4.4.0:*:*:*:*:*:*:*
    • cpe:2.3:a:facebook:hhvm:4.5.0:*:*:*:*:*:*:*
    • cpe:2.3:a:facebook:hhvm:4.6.0:*:*:*:*:*:*:*
    • cpe:2.3:a:facebook:hhvm:4.7.0:*:*:*:*:*:*:*
    • cpe:2.3:a:facebook:hhvm:4.8.0:*:*:*:*:*:*:*
    • (no CPE)range: 4.3.0, 4.4.0, 4.5.0, 4.6.0, 4.7.0, 4.8.0, 3.30.5 and below, and all versions in the 4.0, 4.1, and 4.2 series
    • (no CPE)range: 4.8.1

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.