Site icon API Security Blog

CentOS 8 : php:8.0 (CESA-2022:7624)

The remote CentOS Linux 8 host has packages installed that are affected by multiple vulnerabilities as referenced in the CESA-2022:7624 advisory.

– php: Use after free due to php_filter_float() failing for ints (CVE-2021-21708)

– php: Uninitialized array in pg_query_params() leading to RCE (CVE-2022-31625)

Note that Nessus has not tested for these issues but has instead relied only on the application’s self-reported version number.Read More

Exit mobile version