Unrated severityNVD Advisory· Published Sep 28, 2022· Updated Nov 4, 2025
$_COOKIE names string replacement (. -> _): cookie integrity vulnerabilities
CVE-2022-31629
Description
In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the vulnerability enables network and same-site attackers to set a standard insecure cookie in the victim's browser which is treated as a __Host- or __Secure- cookie by PHP applications.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
12- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2L5SUVYGAKSWODUQPZFBUB3AL6E6CSEV/mitrevendor-advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KJZK3X6B7FBE32FETDSMRLJXTFTHKWSY/mitrevendor-advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LSJVPJTX7T3J5V7XHR4MFNHZGP44R5XE/mitrevendor-advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VI3E6A3ZTH2RP7OMLJHSVFIEQBIFM6RF/mitrevendor-advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XNIEABBH5XCXLFWWZYIDE457SPEDZTXV/mitrevendor-advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZGWIK3HMBACERGB4TSBB2JUOMPYY2VKY/mitrevendor-advisory
- security.gentoo.org/glsa/202211-03mitrevendor-advisory
- www.debian.org/security/2022/dsa-5277mitrevendor-advisory
- www.openwall.com/lists/oss-security/2024/04/12/11mitremailing-list
- lists.debian.org/debian-lts-announce/2022/12/msg00030.htmlmitremailing-list
- bugs.php.net/bug.phpmitre
- security.netapp.com/advisory/ntap-20221209-0001/mitre
News mentions
0No linked articles in our index yet.