CVE-2018-6334
 
Severity Score
9.8
*CVSS v3
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Multipart-file uploads call variables to be improperly registered in the global scope. In cases where variables are not declared explicitly before being used this can lead to unexpected behavior. This affects all supported versions of HHVM prior to the patch (3.25.1, 3.24.5, and 3.21.9 and below).
Subidas del tipo "Multipart-file" llaman a variables para que se registren indebidamente en el ámbito global. En los casos en los que las variables no se declaran explícitamente antes de usarse, esto puede provocar un comportamiento no esperado. Esto afecta a todas las versiones soportadas de HVVM antes del parche (en versiones anteriores a las 3.25.1, 3.24.5 y 3.21.9).
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2018-01-26 CVE Reserved
- 2018-12-31 CVE Published
- 2024-05-23 EPSS Updated
- 2024-08-05 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-20: Improper Input Validation
- CWE-621: Variable Extraction Error
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://github.com/facebook/hhvm/commit/6937de5544c3eead3466b75020d8382080ed0cff | 2019-10-09 | |
https://hhvm.com/blog/2018/03/30/hhvm-3.25.2.html | 2019-10-09 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Facebook Search vendor "Facebook" | Hhvm Search vendor "Facebook" for product "Hhvm" | <= 3.21.9 Search vendor "Facebook" for product "Hhvm" and version " <= 3.21.9" | - |
Affected
| ||||||
Facebook Search vendor "Facebook" | Hhvm Search vendor "Facebook" for product "Hhvm" | >= 3.21.10 <= 3.24.5 Search vendor "Facebook" for product "Hhvm" and version " >= 3.21.10 <= 3.24.5" | - |
Affected
| ||||||
Facebook Search vendor "Facebook" | Hhvm Search vendor "Facebook" for product "Hhvm" | >= 3.24.6 <= 3.25.1 Search vendor "Facebook" for product "Hhvm" and version " >= 3.24.6 <= 3.25.1" | - |
Affected
|