CVE-2021-21707 - log back

CVE-2021-21707 edited at 18 Nov 2021 12:25:47
Severity
- Unknown
+ Low
Remote
- Unknown
+ Remote
Type
- Unknown
+ Insufficient validation
Description
+ A security issue has been found in PHP before versions 8.0.13 and 7.4.26 where a libxml-based XML functions accepting a filename actually accept URIs with possibly percent-encoded characters.
References
+ https://www.php.net/ChangeLog-7.php#7.4.26
+ https://bugs.php.net/bug.php?id=79971
+ https://github.com/php/php-src/commit/763156f0c27905e0b991b399fc57bf38ad53c01c
+ https://github.com/php/php-src/commit/a2e4cbf7c6f00b00cd9b1c13bd6389dfcbffb739
Notes
CVE-2021-21707 created at 18 Nov 2021 12:19:30