← Back

CVE-2019-3569

nvd nist
Published: Jun 26, 2019Modified: Nov 21, 2024

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

HHVM, when used with FastCGI, would bind by default to all available interfaces. This behavior could allow a malicious individual unintended direct access to the application, which could result in information disclosure. This issue affects versions 4.3.0, 4.4.0, 4.5.0, 4.6.0, 4.7.0, 4.8.0, versions 3.30.5 and below, and all versions in the 4.0, 4.1, and 4.2 series.

Affected (14)

Products: Facebook: Hhvm
1 product
Hhvm
Configuration A
14 vulnerable
Vulnerable SoftwareAffected Versions
Facebook
Up to 3.30.5
Version 4.0.0
Version 4.0.1
Version 4.0.2
Version 4.0.3
Version 4.0.4
Version 4.1.0
Version 4.2.0
Version 4.3.0
Version 4.4.0
Version 4.5.0
Version 4.6.0
Version 4.7.0
Version 4.8.0

References (4)

Source: cve-assign@fb.com
Release NotesVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Release NotesVendor Advisory

Timeline

No history available yet.