CVE-2020-7071
Summary
| CVE | CVE-2020-7071 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-02-15 04:15:00 UTC |
| Updated | 2022-08-29 20:05:00 UTC |
| Description | In PHP versions 7.3.x below 7.3.26, 7.4.x below 7.4.14 and 8.0.0, when validating URL with functions like filter_var($url, FILTER_VALIDATE_URL), PHP will accept an URL with invalid password as valid URL. This may lead to functions that rely on URL being valid to mis-parse the URL and produce wrong data as components of the URL. |
Risk And Classification
Problem Types: CWE-20
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Debian | Debian Linux | 10.0 | All | All | All |
| Operating System | Debian | Debian Linux | 9.0 | All | All | All |
| Operating System | Debian | Debian Linux | 10.0 | All | All | All |
| Application | Netapp | Clustered Data Ontap | - | All | All | All |
| Application | Php | Php | All | All | All | All |
| Application | Php | Php | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| February 2021 PHP Vulnerabilities in NetApp Products | NetApp Product Security | CONFIRM | security.netapp.com | |
| [SECURITY] [DLA 2708-1] php7.0 security update | MLIST | lists.debian.org | |
| Debian -- Security Information -- DSA-4856-1 php7.3 | DEBIAN | www.debian.org | Third Party Advisory |
| [R1] Tenable.sc 5.19.0 Fixes Multiple Third-party Vulnerabilities - Security Advisory | Tenable® | CONFIRM | www.tenable.com | |
| Oracle Critical Patch Update Advisory - October 2021 | MISC | www.oracle.com | |
| PHP :: Sec Bug #77423 :: FILTER_VALIDATE_URL accepts URLs with invalid userinfo | CONFIRM | bugs.php.net | Exploit, Issue Tracking, Vendor Advisory |
| PHP: Multiple vulnerabilities (GLSA 202105-23) — Gentoo security | GENTOO | security.gentoo.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Reported by jifan dot jf at alibaba-inc dot com
Legacy QID Mappings
- 150382 PHP Multiple Vulnerabilities (CVE-2020-7071,CVE-2021-21702)
- 159470 Oracle Enterprise Linux Security Update for php:7.4 (ELSA-2021-4213)
- 178707 Debian Security Update for php7.0 (DLA 2708-1)
- 198429 Ubuntu Security Notification for Hypertext Preprocessor vulnerabilities (USN-5006-1)
- 239528 Red Hat Update for rh-php73-php (RHSA-2021:2992)
- 239829 Red Hat Update for php:7.4 security (RHSA-2021:4213)
- 296069 Oracle Solaris 11.4 Support Repository Update (SRU) 31.88.5 Missing (CPUJAN2021)
- 501141 Alpine Linux Security Update for php7
- 501660 Alpine Linux Security Update for php7
- 670246 EulerOS Security Update for php (EulerOS-SA-2021-1830)
- 670664 EulerOS Security Update for php (EulerOS-SA-2021-2423)
- 670892 EulerOS Security Update for Hypertext Preprocessor (PHP) (EulerOS-SA-2021-1163)
- 710093 Gentoo Linux Hypertext Preprocessor Multiple vulnerabilities (GLSA 202105-23)
- 750411 OpenSUSE Security Update for php7 (openSUSE-SU-2021:0106-1)
- 750413 OpenSUSE Security Update for php7 (openSUSE-SU-2021:0101-1)
- 752878 SUSE Enterprise Linux Security Update for php7 (SUSE-SU-2022:4067-1)
- 752898 SUSE Enterprise Linux Security Update for php7 (SUSE-SU-2022:4069-1)
- 752901 SUSE Enterprise Linux Security Update for php74 (SUSE-SU-2022:4068-1)
- 901173 Common Base Linux Mariner (CBL-Mariner) Security Update for Hypertext Preprocessor (PHP) (7323)
- 940558 AlmaLinux Security Update for php:7.4 (ALSA-2021:4213)
- 960309 Rocky Linux Security Update for php:7.4 (RLSA-2021:4213)