CVE-2021-21705
Published on: 10/04/2021 12:00:00 AM UTC
Last Modified on: 10/29/2022 02:50:00 AM UTC
Certain versions of Clustered Data Ontap from Netapp contain the following vulnerability:
In PHP versions 7.3.x below 7.3.29, 7.4.x below 7.4.21 and 8.0.x below 8.0.8, when using URL validation functionality via filter_var() function with FILTER_VALIDATE_URL parameter, an URL with invalid password field can be accepted as valid. This can lead to the code incorrectly parsing the URL and potentially leading to other security implications - like contacting a wrong server or making a wrong access decision.
- CVE-2021-21705 has been assigned by
[email protected] to track the vulnerability - currently rated as MEDIUM severity.
- Affected Vendor/Software:
PHP Group - PHP version < 7.3.29
- Affected Vendor/Software:
PHP Group - PHP version < 7.4.21
- Affected Vendor/Software:
PHP Group - PHP version < 8.0.8
CVSS3 Score: 5.3 - MEDIUM
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | NONE | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | NONE | LOW | NONE |
CVSS2 Score: 5 - MEDIUM
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
NETWORK | LOW | NONE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
NONE | PARTIAL | NONE |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
PHP: Multiple Vulnerabilities (GLSA 202209-20) — Gentoo security | security.gentoo.org text/html |
![]() |
PHP :: Sec Bug #81122 :: SSRF bypass in FILTER_VALIDATE_URL | bugs.php.net text/html |
![]() |
Oracle Critical Patch Update Advisory - January 2022 | www.oracle.com text/html |
![]() |
September 2021 PHP Vulnerabilities in NetApp Products | NetApp Product Security | security.netapp.com text/html |
![]() |
Related QID Numbers
- 150469 PHP Multiple Vulnerabilities (CVE-2021-21704,CVE-2021-21705)
- 159834 Oracle Enterprise Linux Security Update for php:7.4 (ELSA-2022-1935)
- 178696 Debian Security Update for php7.3 (DSA 4935-1)
- 178707 Debian Security Update for php7.0 (DLA 2708-1)
- 180055 Debian Security Update for php7.4 (CVE-2021-21705)
- 198429 Ubuntu Security Notification for Hypertext Preprocessor vulnerabilities (USN-5006-1)
- 239528 Red Hat Update for rh-php73-php (RHSA-2021:2992)
- 240318 Red Hat Update for php:7.4 (RHSA-2022:1935)
- 281697 Fedora Security Update for php (FEDORA-2021-d867b595d1)
- 281698 Fedora Security Update for php (FEDORA-2021-172c8bd11d)
- 352803 Amazon Linux Security Advisory for php73: ALAS-2021-1532
- 38844 PHP Multiple Security Vulnerabilities
- 501143 Alpine Linux Security Update for php7
- 501662 Alpine Linux Security Update for php7
- 501670 Alpine Linux Security Update for php8
- 670721 EulerOS Security Update for php (EulerOS-SA-2021-2479)
- 710633 Gentoo Linux Hypertext Preprocessor (PHP) Multiple Vulnerabilities (GLSA 202209-20)
- 750905 SUSE Enterprise Linux Security Update for php72 (SUSE-SU-2021:2564-1)
- 750908 OpenSUSE Security Update for php7 (openSUSE-SU-2021:2575-1)
- 750933 SUSE Enterprise Linux Security Update for php74 (SUSE-SU-2021:2636-1)
- 750937 OpenSUSE Security Update for php7 (openSUSE-SU-2021:2637-1)
- 750952 OpenSUSE Security Update for php7 (openSUSE-SU-2021:1130-1)
- 752878 SUSE Enterprise Linux Security Update for php7 (SUSE-SU-2022:4067-1)
- 752898 SUSE Enterprise Linux Security Update for php7 (SUSE-SU-2022:4069-1)
- 752901 SUSE Enterprise Linux Security Update for php74 (SUSE-SU-2022:4068-1)
- 901129 Common Base Linux Mariner (CBL-Mariner) Security Update for Hypertext Preprocessor (PHP) (7327)
- 940552 AlmaLinux Security Update for php:7.4 (ALSA-2022:1935)
- 960280 Rocky Linux Security Update for php:7.4 (RLSA-2022:1935)
Exploit/POC from Github
In PHP versions 7.3.x below 7.3.29, 7.4.x below 7.4.21 and 8.0.x below 8.0.8, when using URL validation functionality…
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Netapp | Clustered Data Ontap | - | All | All | All |
Application | Oracle | Sd-wan Aware | 8.2 | All | All | All |
Application | Php | Php | All | All | All | All |
- cpe:2.3:a:netapp:clustered_data_ontap:-:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:sd-wan_aware:8.2:*:*:*:*:*:*:*:
- cpe:2.3:a:php:php:*:*:*:*:*:*:*:*:
Discovery Credit
reported by vi at hackberry dot xyz
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
PHP 8.0.8の脆弱性は2つ 今回のPHPはこれの修正がメインになりそう (CVE-2021-21704)はPDO_Firebirdを使ってないから、影響受けなさそう。 (CVE-2021-21705)はコアに検証フィルタ を… twitter.com/i/web/status/1… | 2021-06-29 12:47:18 |
![]() |
PHP 8.0.8, 7.4.21 a 7.3.29 řeší bezpečnostní chyby CVE-2021-21704 a CVE-2021-21705 abclinuxu.cz/zpravicky/php-… | 2021-07-01 16:57:06 |
![]() |
Heads-up: ECR's Container Image Scanner doesn't seem to catch CVE-2021-21705 in PHP <8.0.8, at least not with the p… twitter.com/i/web/status/1… | 2021-07-08 08:46:07 |
![]() |
PHPの脆弱性情報(Moderate: CVE-2021-21704, CVE-2021-21705)と新バージョン(7.3.29, 7.4.21, 8.0.8) security.sios.com/vulnerability/… | 2021-07-10 06:11:09 |
![]() |
CVE-2021-21705 : In PHP versions 7.3.x below 7.3.29, 7.4.x below 7.4.21 and 8.0.x below 8.0.8, when using URL valid… twitter.com/i/web/status/1… | 2021-10-04 04:04:16 |
![]() |
New vulnerability on the NVD: CVE-2021-21705 ift.tt/3iwVMit | 2021-10-04 05:33:58 |
![]() |
New vulnerability on the NVD: CVE-2021-21705 ift.tt/3iwVMit | 2021-10-04 05:40:48 |
![]() |
CVE-2021-21705 ift.tt/3iwVMit | 2021-10-04 05:52:07 |
![]() |
Php - CVE-2021-21705: bugs.php.net/bug.php?id=811… | 2021-10-04 06:16:57 |
![]() |
RT: CVE-2021-21705 In PHP versions 7.3.x below 7.3.29, 7.4.x below 7.4.21 and 8.0.x below 8.0.8, when using URL va… twitter.com/i/web/status/1… | 2021-10-04 07:33:34 |
![]() |
PHP security release 8.0.8, 7.4.21, and 7.3.29 | 2021-07-01 15:05:15 |