Vulnerability Bulletins

MSA-23-0019: Proxy bypass risk due to insufficient validation


System information

   
Affected software PHP

Description

von Michael Hawkins. Incorrect domain matching logic made it possible to bypass the proxy, which could result in access to hosts intended to be blocked by the proxy.Severity/Risk:SeriousVersions affected:4.2 to 4.2.1, 4.1 to 4.1.4, 4.0 to 4.0.9, 3.11 to 3.11.15, 3.9 to 3.9.22 and earlier unsupported versionsVersions fixed:4.2.2, 4.1.5, 4.0.10, 3.11.16 and 3.9.23Reported by:Brendan HeywoodWorkaround:Add hosts blocked within the proxy to the Moodle cURL blocked hosts configuration if possible,

More info:

https://moodle.org/mod/forum/discuss.php?d=449640&parent=1807042

Standar resources

Property Value
CVE

Version history

Version Comments Date
Ministerio de Defensa
CNI
CCN
CCN-CERT