In PHP 8.0.X before 8.0.28, 8.1.X before 8.1.16 and 8.2.X before 8.2.3, password_verify() function may accept some invalid Blowfish hashes as valid. If such invalid hash ever ends up in the password …
High CVSS 7.7
Summary
In PHP 8.0.X before 8.0.28, 8.1.X before 8.1.16 and 8.2.X before 8.2.3, password_verify() function may accept some invalid Blowfish hashes as valid. If such invalid hash ever ends up in the password database, it may lead to an application allowing any password for this entry as valid.
In-depth triage · Auto channel
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
Sources
- NVD DATABASE
Original Links
- https://bugs.php.net/bug.php?id=81744 Vendor Advisory
- https://github.com/php/php-src/security/advisories/GHSA-7fj2-8x79-rjf4 Exploit
- https://security.netapp.com/advisory/ntap-20230331-0008/
Timeline
- nvd_ingest NVD