CVE-2019-3569
Summary
| CVE | CVE-2019-3569 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-06-26 15:15:00 UTC |
| Updated | 2021-09-14 12:19:00 UTC |
| Description | HHVM, when used with FastCGI, would bind by default to all available interfaces. This behavior could allow a malicious individual unintended direct access to the application, which could result in information disclosure. This issue affects versions 4.3.0, 4.4.0, 4.5.0, 4.6.0, 4.7.0, 4.8.0, versions 3.30.5 and below, and all versions in the 4.0, 4.1, and 4.2 series. |
Risk And Classification
Problem Types: CWE-668
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Hhvm | 4.0.0 | All | All | All | |
| Application | Hhvm | 4.0.1 | All | All | All | |
| Application | Hhvm | 4.0.2 | All | All | All | |
| Application | Hhvm | 4.0.3 | All | All | All | |
| Application | Hhvm | 4.0.4 | All | All | All | |
| Application | Hhvm | 4.1.0 | All | All | All | |
| Application | Hhvm | 4.2.0 | All | All | All | |
| Application | Hhvm | 4.3.0 | All | All | All | |
| Application | Hhvm | 4.4.0 | All | All | All | |
| Application | Hhvm | 4.5.0 | All | All | All | |
| Application | Hhvm | 4.6.0 | All | All | All | |
| Application | Hhvm | 4.7.0 | All | All | All | |
| Application | Hhvm | 4.8.0 | All | All | All | |
| Application | Hhvm | 4.0.0 | All | All | All | |
| Application | Hhvm | 4.0.1 | All | All | All | |
| Application | Hhvm | 4.0.2 | All | All | All | |
| Application | Hhvm | 4.0.3 | All | All | All | |
| Application | Hhvm | 4.0.4 | All | All | All | |
| Application | Hhvm | 4.1.0 | All | All | All | |
| Application | Hhvm | 4.2.0 | All | All | All | |
| Application | Hhvm | 4.3.0 | All | All | All | |
| Application | Hhvm | 4.4.0 | All | All | All | |
| Application | Hhvm | 4.5.0 | All | All | All | |
| Application | Hhvm | 4.6.0 | All | All | All | |
| Application | Hhvm | 4.7.0 | All | All | All | |
| Application | Hhvm | 4.8.0 | All | All | All | |
| Application | Hhvm | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Fix default FastCGI interface · facebook/hhvm@97ef580 · GitHub | MISC | github.com | Patch, Third Party Advisory |
| HHVM 4.9.0, and security updates for 3.30, and 4.3-4.7 | HHVM | MISC | hhvm.com | Release Notes, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.