CVE-2021-21705 log

Source
Severity Medium
Remote Yes
Type Insufficient validation
Description
A security issue was found in the php_url_parse_ex() function in PHP before versions 8.0.8 and 7.4.21, which leads to FILTER_VALIDATE_URL accepting URLs with invalid userinfo, a different issue from CVE-2020-7071.
Group Package Affected Fixed Severity Status Ticket
AVG-2133 php7 7.4.20-1 7.4.21-1 Medium Fixed
AVG-2132 php 8.0.7-1 8.0.8-1 Medium Fixed
Date Advisory Group Package Severity Type
06 Jul 2021 ASA-202107-16 AVG-2133 php7 Medium multiple issues
06 Jul 2021 ASA-202107-15 AVG-2132 php Medium multiple issues
References
https://www.php.net/ChangeLog-8.php#8.0.8
https://www.php.net/ChangeLog-7.php#7.4.21
https://bugs.php.net/bug.php?id=81122
https://github.com/php/php-src/commit/5a1fe88ac120d71064bdd314dce1e49c86ff0585
https://github.com/php/php-src/commit/5cea97e083448aaa2352320612541c895178b3b5