amphp/artax
Asynchronous parallel HTTP/1.1 client built on the Amp concurrency framework
Activity
- Latest release
- 8y ago
- Total releases
- 49
- Cadence
- ~5 days
- Last 12 months
- 0
Reach
- Stars
- —
Details
- License
- MIT
- First release
- Dec 16, 2012
| Version | Released | |
|---|---|---|
v3.0.14
patch
deprecated
| ||
v3.0.13
patch
| ||
v3.0.12
patch
| ||
v3.0.11
patch
| ||
v3.0.10
patch
| ||
v3.0.9
patch
| ||
v3.0.8
patch
| ||
v3.0.7
patch
| ||
v3.0.6
patch
| ||
v3.0.5
patch
| ||
v3.0.4
patch
| ||
v2.0.7
patch
| ||
v3.0.3
patch
| ||
v3.0.2
patch
| ||
v3.0.1
patch
| ||
v3.0.0
major
| ||
v2.0.6
patch
| ||
v1.0.6
patch
| ||
v1.0.5
patch
1 CVE
GHSA-gm98-g2wf-7c68
May 15, 2024
amphp/artax Cookie leakage to wrong origins and non-restricted cookie acceptance
Medium
In artax version before 1.0.6 and 2 before 2.0.6, cookies of Affected versions
2.0.2
v2.0.0
v2.0.1
v2.0.3
v2.0.4
v2.0.5
v0.1.0
v0.3.7
v0.4.0
v0.5.0
v0.5.1
v0.6.0
+ 19 more Show less
v0.6.1
v0.6.2
v0.7.0
v0.7.1
v1.0.0
v1.0.0-alpha
v1.0.0-beta
v1.0.0-beta2
v1.0.0-rc1
v1.0.0-rc2
v1.0.0-rc3
v1.0.0-rc4
v1.0.0-rc5
v1.0.0-rc6
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
Fixed in
1.0.6
2.0.6
References
Updated Nov 29, 2024 · Source: OSV.dev | ||
v2.0.5
patch
1 CVE
GHSA-gm98-g2wf-7c68
May 15, 2024
amphp/artax Cookie leakage to wrong origins and non-restricted cookie acceptance
Medium
In artax version before 1.0.6 and 2 before 2.0.6, cookies of Affected versions
2.0.2
v2.0.0
v2.0.1
v2.0.3
v2.0.4
v2.0.5
v0.1.0
v0.3.7
v0.4.0
v0.5.0
v0.5.1
v0.6.0
+ 19 more Show less
v0.6.1
v0.6.2
v0.7.0
v0.7.1
v1.0.0
v1.0.0-alpha
v1.0.0-beta
v1.0.0-beta2
v1.0.0-rc1
v1.0.0-rc2
v1.0.0-rc3
v1.0.0-rc4
v1.0.0-rc5
v1.0.0-rc6
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
Fixed in
1.0.6
2.0.6
References
Updated Nov 29, 2024 · Source: OSV.dev | ||
v2.0.4
patch
1 CVE
GHSA-gm98-g2wf-7c68
May 15, 2024
amphp/artax Cookie leakage to wrong origins and non-restricted cookie acceptance
Medium
In artax version before 1.0.6 and 2 before 2.0.6, cookies of Affected versions
2.0.2
v2.0.0
v2.0.1
v2.0.3
v2.0.4
v2.0.5
v0.1.0
v0.3.7
v0.4.0
v0.5.0
v0.5.1
v0.6.0
+ 19 more Show less
v0.6.1
v0.6.2
v0.7.0
v0.7.1
v1.0.0
v1.0.0-alpha
v1.0.0-beta
v1.0.0-beta2
v1.0.0-rc1
v1.0.0-rc2
v1.0.0-rc3
v1.0.0-rc4
v1.0.0-rc5
v1.0.0-rc6
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
Fixed in
1.0.6
2.0.6
References
Updated Nov 29, 2024 · Source: OSV.dev | ||
v1.0.4
patch
1 CVE
GHSA-gm98-g2wf-7c68
May 15, 2024
amphp/artax Cookie leakage to wrong origins and non-restricted cookie acceptance
Medium
In artax version before 1.0.6 and 2 before 2.0.6, cookies of Affected versions
2.0.2
v2.0.0
v2.0.1
v2.0.3
v2.0.4
v2.0.5
v0.1.0
v0.3.7
v0.4.0
v0.5.0
v0.5.1
v0.6.0
+ 19 more Show less
v0.6.1
v0.6.2
v0.7.0
v0.7.1
v1.0.0
v1.0.0-alpha
v1.0.0-beta
v1.0.0-beta2
v1.0.0-rc1
v1.0.0-rc2
v1.0.0-rc3
v1.0.0-rc4
v1.0.0-rc5
v1.0.0-rc6
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
Fixed in
1.0.6
2.0.6
References
Updated Nov 29, 2024 · Source: OSV.dev | ||
v1.0.3
patch
2 CVEs
GHSA-gm98-g2wf-7c68
May 15, 2024
amphp/artax Cookie leakage to wrong origins and non-restricted cookie acceptance
Medium
In artax version before 1.0.6 and 2 before 2.0.6, cookies of Affected versions
2.0.2
v2.0.0
v2.0.1
v2.0.3
v2.0.4
v2.0.5
v0.1.0
v0.3.7
v0.4.0
v0.5.0
v0.5.1
v0.6.0
+ 19 more Show less
v0.6.1
v0.6.2
v0.7.0
v0.7.1
v1.0.0
v1.0.0-alpha
v1.0.0-beta
v1.0.0-beta2
v1.0.0-rc1
v1.0.0-rc2
v1.0.0-rc3
v1.0.0-rc4
v1.0.0-rc5
v1.0.0-rc6
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
Fixed in
1.0.6
2.0.6
References
Updated Nov 29, 2024 · Source: OSV.dev
CVE-2016-5385
GHSA-m6ch-gg5f-wxx3
Apr 07, 2022
HTTP Proxy header vulnerability
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
PHP through 7.0.8 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, as demonstrated by (1) an application that makes a getenv('HTTP_PROXY') call or (2) a CGI configuration of PHP, aka an "httpoxy" issue. Affected versions
v0.1.0
v0.3.7
v0.4.0
v0.5.0
v0.5.1
v0.6.0
v0.6.1
v0.6.2
v0.7.0
v0.7.1
v1.0.0
v1.0.0-alpha
+ 15 more Show less
v1.0.0-beta
v1.0.0-beta2
v1.0.0-rc1
v1.0.0-rc2
v1.0.0-rc3
v1.0.0-rc4
v1.0.0-rc5
v1.0.0-rc6
v1.0.1
v1.0.2
v1.0.3
2.0.2
v2.0.0
v2.0.1
v2.0.3
Fixed in
1.0.4
2.0.4
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
v2.0.3
patch
2 CVEs
GHSA-gm98-g2wf-7c68
May 15, 2024
amphp/artax Cookie leakage to wrong origins and non-restricted cookie acceptance
Medium
In artax version before 1.0.6 and 2 before 2.0.6, cookies of Affected versions
2.0.2
v2.0.0
v2.0.1
v2.0.3
v2.0.4
v2.0.5
v0.1.0
v0.3.7
v0.4.0
v0.5.0
v0.5.1
v0.6.0
+ 19 more Show less
v0.6.1
v0.6.2
v0.7.0
v0.7.1
v1.0.0
v1.0.0-alpha
v1.0.0-beta
v1.0.0-beta2
v1.0.0-rc1
v1.0.0-rc2
v1.0.0-rc3
v1.0.0-rc4
v1.0.0-rc5
v1.0.0-rc6
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
Fixed in
1.0.6
2.0.6
References
Updated Nov 29, 2024 · Source: OSV.dev
CVE-2016-5385
GHSA-m6ch-gg5f-wxx3
Apr 07, 2022
HTTP Proxy header vulnerability
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
PHP through 7.0.8 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, as demonstrated by (1) an application that makes a getenv('HTTP_PROXY') call or (2) a CGI configuration of PHP, aka an "httpoxy" issue. Affected versions
v0.1.0
v0.3.7
v0.4.0
v0.5.0
v0.5.1
v0.6.0
v0.6.1
v0.6.2
v0.7.0
v0.7.1
v1.0.0
v1.0.0-alpha
+ 15 more Show less
v1.0.0-beta
v1.0.0-beta2
v1.0.0-rc1
v1.0.0-rc2
v1.0.0-rc3
v1.0.0-rc4
v1.0.0-rc5
v1.0.0-rc6
v1.0.1
v1.0.2
v1.0.3
2.0.2
v2.0.0
v2.0.1
v2.0.3
Fixed in
1.0.4
2.0.4
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
2.0.2
patch
2 CVEs
GHSA-gm98-g2wf-7c68
May 15, 2024
amphp/artax Cookie leakage to wrong origins and non-restricted cookie acceptance
Medium
In artax version before 1.0.6 and 2 before 2.0.6, cookies of Affected versions
2.0.2
v2.0.0
v2.0.1
v2.0.3
v2.0.4
v2.0.5
v0.1.0
v0.3.7
v0.4.0
v0.5.0
v0.5.1
v0.6.0
+ 19 more Show less
v0.6.1
v0.6.2
v0.7.0
v0.7.1
v1.0.0
v1.0.0-alpha
v1.0.0-beta
v1.0.0-beta2
v1.0.0-rc1
v1.0.0-rc2
v1.0.0-rc3
v1.0.0-rc4
v1.0.0-rc5
v1.0.0-rc6
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
Fixed in
1.0.6
2.0.6
References
Updated Nov 29, 2024 · Source: OSV.dev
CVE-2016-5385
GHSA-m6ch-gg5f-wxx3
Apr 07, 2022
HTTP Proxy header vulnerability
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
PHP through 7.0.8 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, as demonstrated by (1) an application that makes a getenv('HTTP_PROXY') call or (2) a CGI configuration of PHP, aka an "httpoxy" issue. Affected versions
v0.1.0
v0.3.7
v0.4.0
v0.5.0
v0.5.1
v0.6.0
v0.6.1
v0.6.2
v0.7.0
v0.7.1
v1.0.0
v1.0.0-alpha
+ 15 more Show less
v1.0.0-beta
v1.0.0-beta2
v1.0.0-rc1
v1.0.0-rc2
v1.0.0-rc3
v1.0.0-rc4
v1.0.0-rc5
v1.0.0-rc6
v1.0.1
v1.0.2
v1.0.3
2.0.2
v2.0.0
v2.0.1
v2.0.3
Fixed in
1.0.4
2.0.4
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
v2.0.1
patch
2 CVEs
GHSA-gm98-g2wf-7c68
May 15, 2024
amphp/artax Cookie leakage to wrong origins and non-restricted cookie acceptance
Medium
In artax version before 1.0.6 and 2 before 2.0.6, cookies of Affected versions
2.0.2
v2.0.0
v2.0.1
v2.0.3
v2.0.4
v2.0.5
v0.1.0
v0.3.7
v0.4.0
v0.5.0
v0.5.1
v0.6.0
+ 19 more Show less
v0.6.1
v0.6.2
v0.7.0
v0.7.1
v1.0.0
v1.0.0-alpha
v1.0.0-beta
v1.0.0-beta2
v1.0.0-rc1
v1.0.0-rc2
v1.0.0-rc3
v1.0.0-rc4
v1.0.0-rc5
v1.0.0-rc6
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
Fixed in
1.0.6
2.0.6
References
Updated Nov 29, 2024 · Source: OSV.dev
CVE-2016-5385
GHSA-m6ch-gg5f-wxx3
Apr 07, 2022
HTTP Proxy header vulnerability
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
PHP through 7.0.8 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, as demonstrated by (1) an application that makes a getenv('HTTP_PROXY') call or (2) a CGI configuration of PHP, aka an "httpoxy" issue. Affected versions
v0.1.0
v0.3.7
v0.4.0
v0.5.0
v0.5.1
v0.6.0
v0.6.1
v0.6.2
v0.7.0
v0.7.1
v1.0.0
v1.0.0-alpha
+ 15 more Show less
v1.0.0-beta
v1.0.0-beta2
v1.0.0-rc1
v1.0.0-rc2
v1.0.0-rc3
v1.0.0-rc4
v1.0.0-rc5
v1.0.0-rc6
v1.0.1
v1.0.2
v1.0.3
2.0.2
v2.0.0
v2.0.1
v2.0.3
Fixed in
1.0.4
2.0.4
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
v1.0.2
patch
2 CVEs
GHSA-gm98-g2wf-7c68
May 15, 2024
amphp/artax Cookie leakage to wrong origins and non-restricted cookie acceptance
Medium
In artax version before 1.0.6 and 2 before 2.0.6, cookies of Affected versions
2.0.2
v2.0.0
v2.0.1
v2.0.3
v2.0.4
v2.0.5
v0.1.0
v0.3.7
v0.4.0
v0.5.0
v0.5.1
v0.6.0
+ 19 more Show less
v0.6.1
v0.6.2
v0.7.0
v0.7.1
v1.0.0
v1.0.0-alpha
v1.0.0-beta
v1.0.0-beta2
v1.0.0-rc1
v1.0.0-rc2
v1.0.0-rc3
v1.0.0-rc4
v1.0.0-rc5
v1.0.0-rc6
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
Fixed in
1.0.6
2.0.6
References
Updated Nov 29, 2024 · Source: OSV.dev
CVE-2016-5385
GHSA-m6ch-gg5f-wxx3
Apr 07, 2022
HTTP Proxy header vulnerability
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
PHP through 7.0.8 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, as demonstrated by (1) an application that makes a getenv('HTTP_PROXY') call or (2) a CGI configuration of PHP, aka an "httpoxy" issue. Affected versions
v0.1.0
v0.3.7
v0.4.0
v0.5.0
v0.5.1
v0.6.0
v0.6.1
v0.6.2
v0.7.0
v0.7.1
v1.0.0
v1.0.0-alpha
+ 15 more Show less
v1.0.0-beta
v1.0.0-beta2
v1.0.0-rc1
v1.0.0-rc2
v1.0.0-rc3
v1.0.0-rc4
v1.0.0-rc5
v1.0.0-rc6
v1.0.1
v1.0.2
v1.0.3
2.0.2
v2.0.0
v2.0.1
v2.0.3
Fixed in
1.0.4
2.0.4
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
v2.0.0
major
2 CVEs
GHSA-gm98-g2wf-7c68
May 15, 2024
amphp/artax Cookie leakage to wrong origins and non-restricted cookie acceptance
Medium
In artax version before 1.0.6 and 2 before 2.0.6, cookies of Affected versions
2.0.2
v2.0.0
v2.0.1
v2.0.3
v2.0.4
v2.0.5
v0.1.0
v0.3.7
v0.4.0
v0.5.0
v0.5.1
v0.6.0
+ 19 more Show less
v0.6.1
v0.6.2
v0.7.0
v0.7.1
v1.0.0
v1.0.0-alpha
v1.0.0-beta
v1.0.0-beta2
v1.0.0-rc1
v1.0.0-rc2
v1.0.0-rc3
v1.0.0-rc4
v1.0.0-rc5
v1.0.0-rc6
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
Fixed in
1.0.6
2.0.6
References
Updated Nov 29, 2024 · Source: OSV.dev
CVE-2016-5385
GHSA-m6ch-gg5f-wxx3
Apr 07, 2022
HTTP Proxy header vulnerability
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
PHP through 7.0.8 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, as demonstrated by (1) an application that makes a getenv('HTTP_PROXY') call or (2) a CGI configuration of PHP, aka an "httpoxy" issue. Affected versions
v0.1.0
v0.3.7
v0.4.0
v0.5.0
v0.5.1
v0.6.0
v0.6.1
v0.6.2
v0.7.0
v0.7.1
v1.0.0
v1.0.0-alpha
+ 15 more Show less
v1.0.0-beta
v1.0.0-beta2
v1.0.0-rc1
v1.0.0-rc2
v1.0.0-rc3
v1.0.0-rc4
v1.0.0-rc5
v1.0.0-rc6
v1.0.1
v1.0.2
v1.0.3
2.0.2
v2.0.0
v2.0.1
v2.0.3
Fixed in
1.0.4
2.0.4
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
v1.0.1
patch
2 CVEs
GHSA-gm98-g2wf-7c68
May 15, 2024
amphp/artax Cookie leakage to wrong origins and non-restricted cookie acceptance
Medium
In artax version before 1.0.6 and 2 before 2.0.6, cookies of Affected versions
2.0.2
v2.0.0
v2.0.1
v2.0.3
v2.0.4
v2.0.5
v0.1.0
v0.3.7
v0.4.0
v0.5.0
v0.5.1
v0.6.0
+ 19 more Show less
v0.6.1
v0.6.2
v0.7.0
v0.7.1
v1.0.0
v1.0.0-alpha
v1.0.0-beta
v1.0.0-beta2
v1.0.0-rc1
v1.0.0-rc2
v1.0.0-rc3
v1.0.0-rc4
v1.0.0-rc5
v1.0.0-rc6
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
Fixed in
1.0.6
2.0.6
References
Updated Nov 29, 2024 · Source: OSV.dev
CVE-2016-5385
GHSA-m6ch-gg5f-wxx3
Apr 07, 2022
HTTP Proxy header vulnerability
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
PHP through 7.0.8 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, as demonstrated by (1) an application that makes a getenv('HTTP_PROXY') call or (2) a CGI configuration of PHP, aka an "httpoxy" issue. Affected versions
v0.1.0
v0.3.7
v0.4.0
v0.5.0
v0.5.1
v0.6.0
v0.6.1
v0.6.2
v0.7.0
v0.7.1
v1.0.0
v1.0.0-alpha
+ 15 more Show less
v1.0.0-beta
v1.0.0-beta2
v1.0.0-rc1
v1.0.0-rc2
v1.0.0-rc3
v1.0.0-rc4
v1.0.0-rc5
v1.0.0-rc6
v1.0.1
v1.0.2
v1.0.3
2.0.2
v2.0.0
v2.0.1
v2.0.3
Fixed in
1.0.4
2.0.4
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
v1.0.0
major
2 CVEs
GHSA-gm98-g2wf-7c68
May 15, 2024
amphp/artax Cookie leakage to wrong origins and non-restricted cookie acceptance
Medium
In artax version before 1.0.6 and 2 before 2.0.6, cookies of Affected versions
2.0.2
v2.0.0
v2.0.1
v2.0.3
v2.0.4
v2.0.5
v0.1.0
v0.3.7
v0.4.0
v0.5.0
v0.5.1
v0.6.0
+ 19 more Show less
v0.6.1
v0.6.2
v0.7.0
v0.7.1
v1.0.0
v1.0.0-alpha
v1.0.0-beta
v1.0.0-beta2
v1.0.0-rc1
v1.0.0-rc2
v1.0.0-rc3
v1.0.0-rc4
v1.0.0-rc5
v1.0.0-rc6
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
Fixed in
1.0.6
2.0.6
References
Updated Nov 29, 2024 · Source: OSV.dev
CVE-2016-5385
GHSA-m6ch-gg5f-wxx3
Apr 07, 2022
HTTP Proxy header vulnerability
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
PHP through 7.0.8 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, as demonstrated by (1) an application that makes a getenv('HTTP_PROXY') call or (2) a CGI configuration of PHP, aka an "httpoxy" issue. Affected versions
v0.1.0
v0.3.7
v0.4.0
v0.5.0
v0.5.1
v0.6.0
v0.6.1
v0.6.2
v0.7.0
v0.7.1
v1.0.0
v1.0.0-alpha
+ 15 more Show less
v1.0.0-beta
v1.0.0-beta2
v1.0.0-rc1
v1.0.0-rc2
v1.0.0-rc3
v1.0.0-rc4
v1.0.0-rc5
v1.0.0-rc6
v1.0.1
v1.0.2
v1.0.3
2.0.2
v2.0.0
v2.0.1
v2.0.3
Fixed in
1.0.4
2.0.4
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
v1.0.0-rc6
pre
2 CVEs
GHSA-gm98-g2wf-7c68
May 15, 2024
amphp/artax Cookie leakage to wrong origins and non-restricted cookie acceptance
Medium
In artax version before 1.0.6 and 2 before 2.0.6, cookies of Affected versions
2.0.2
v2.0.0
v2.0.1
v2.0.3
v2.0.4
v2.0.5
v0.1.0
v0.3.7
v0.4.0
v0.5.0
v0.5.1
v0.6.0
+ 19 more Show less
v0.6.1
v0.6.2
v0.7.0
v0.7.1
v1.0.0
v1.0.0-alpha
v1.0.0-beta
v1.0.0-beta2
v1.0.0-rc1
v1.0.0-rc2
v1.0.0-rc3
v1.0.0-rc4
v1.0.0-rc5
v1.0.0-rc6
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
Fixed in
1.0.6
2.0.6
References
Updated Nov 29, 2024 · Source: OSV.dev
CVE-2016-5385
GHSA-m6ch-gg5f-wxx3
Apr 07, 2022
HTTP Proxy header vulnerability
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
PHP through 7.0.8 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, as demonstrated by (1) an application that makes a getenv('HTTP_PROXY') call or (2) a CGI configuration of PHP, aka an "httpoxy" issue. Affected versions
v0.1.0
v0.3.7
v0.4.0
v0.5.0
v0.5.1
v0.6.0
v0.6.1
v0.6.2
v0.7.0
v0.7.1
v1.0.0
v1.0.0-alpha
+ 15 more Show less
v1.0.0-beta
v1.0.0-beta2
v1.0.0-rc1
v1.0.0-rc2
v1.0.0-rc3
v1.0.0-rc4
v1.0.0-rc5
v1.0.0-rc6
v1.0.1
v1.0.2
v1.0.3
2.0.2
v2.0.0
v2.0.1
v2.0.3
Fixed in
1.0.4
2.0.4
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
v1.0.0-rc5
pre
2 CVEs
GHSA-gm98-g2wf-7c68
May 15, 2024
amphp/artax Cookie leakage to wrong origins and non-restricted cookie acceptance
Medium
In artax version before 1.0.6 and 2 before 2.0.6, cookies of Affected versions
2.0.2
v2.0.0
v2.0.1
v2.0.3
v2.0.4
v2.0.5
v0.1.0
v0.3.7
v0.4.0
v0.5.0
v0.5.1
v0.6.0
+ 19 more Show less
v0.6.1
v0.6.2
v0.7.0
v0.7.1
v1.0.0
v1.0.0-alpha
v1.0.0-beta
v1.0.0-beta2
v1.0.0-rc1
v1.0.0-rc2
v1.0.0-rc3
v1.0.0-rc4
v1.0.0-rc5
v1.0.0-rc6
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
Fixed in
1.0.6
2.0.6
References
Updated Nov 29, 2024 · Source: OSV.dev
CVE-2016-5385
GHSA-m6ch-gg5f-wxx3
Apr 07, 2022
HTTP Proxy header vulnerability
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
PHP through 7.0.8 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, as demonstrated by (1) an application that makes a getenv('HTTP_PROXY') call or (2) a CGI configuration of PHP, aka an "httpoxy" issue. Affected versions
v0.1.0
v0.3.7
v0.4.0
v0.5.0
v0.5.1
v0.6.0
v0.6.1
v0.6.2
v0.7.0
v0.7.1
v1.0.0
v1.0.0-alpha
+ 15 more Show less
v1.0.0-beta
v1.0.0-beta2
v1.0.0-rc1
v1.0.0-rc2
v1.0.0-rc3
v1.0.0-rc4
v1.0.0-rc5
v1.0.0-rc6
v1.0.1
v1.0.2
v1.0.3
2.0.2
v2.0.0
v2.0.1
v2.0.3
Fixed in
1.0.4
2.0.4
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
v1.0.0-rc4
pre
2 CVEs
GHSA-gm98-g2wf-7c68
May 15, 2024
amphp/artax Cookie leakage to wrong origins and non-restricted cookie acceptance
Medium
In artax version before 1.0.6 and 2 before 2.0.6, cookies of Affected versions
2.0.2
v2.0.0
v2.0.1
v2.0.3
v2.0.4
v2.0.5
v0.1.0
v0.3.7
v0.4.0
v0.5.0
v0.5.1
v0.6.0
+ 19 more Show less
v0.6.1
v0.6.2
v0.7.0
v0.7.1
v1.0.0
v1.0.0-alpha
v1.0.0-beta
v1.0.0-beta2
v1.0.0-rc1
v1.0.0-rc2
v1.0.0-rc3
v1.0.0-rc4
v1.0.0-rc5
v1.0.0-rc6
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
Fixed in
1.0.6
2.0.6
References
Updated Nov 29, 2024 · Source: OSV.dev
CVE-2016-5385
GHSA-m6ch-gg5f-wxx3
Apr 07, 2022
HTTP Proxy header vulnerability
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
PHP through 7.0.8 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, as demonstrated by (1) an application that makes a getenv('HTTP_PROXY') call or (2) a CGI configuration of PHP, aka an "httpoxy" issue. Affected versions
v0.1.0
v0.3.7
v0.4.0
v0.5.0
v0.5.1
v0.6.0
v0.6.1
v0.6.2
v0.7.0
v0.7.1
v1.0.0
v1.0.0-alpha
+ 15 more Show less
v1.0.0-beta
v1.0.0-beta2
v1.0.0-rc1
v1.0.0-rc2
v1.0.0-rc3
v1.0.0-rc4
v1.0.0-rc5
v1.0.0-rc6
v1.0.1
v1.0.2
v1.0.3
2.0.2
v2.0.0
v2.0.1
v2.0.3
Fixed in
1.0.4
2.0.4
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
v1.0.0-rc3
pre
2 CVEs
GHSA-gm98-g2wf-7c68
May 15, 2024
amphp/artax Cookie leakage to wrong origins and non-restricted cookie acceptance
Medium
In artax version before 1.0.6 and 2 before 2.0.6, cookies of Affected versions
2.0.2
v2.0.0
v2.0.1
v2.0.3
v2.0.4
v2.0.5
v0.1.0
v0.3.7
v0.4.0
v0.5.0
v0.5.1
v0.6.0
+ 19 more Show less
v0.6.1
v0.6.2
v0.7.0
v0.7.1
v1.0.0
v1.0.0-alpha
v1.0.0-beta
v1.0.0-beta2
v1.0.0-rc1
v1.0.0-rc2
v1.0.0-rc3
v1.0.0-rc4
v1.0.0-rc5
v1.0.0-rc6
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
Fixed in
1.0.6
2.0.6
References
Updated Nov 29, 2024 · Source: OSV.dev
CVE-2016-5385
GHSA-m6ch-gg5f-wxx3
Apr 07, 2022
HTTP Proxy header vulnerability
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
PHP through 7.0.8 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, as demonstrated by (1) an application that makes a getenv('HTTP_PROXY') call or (2) a CGI configuration of PHP, aka an "httpoxy" issue. Affected versions
v0.1.0
v0.3.7
v0.4.0
v0.5.0
v0.5.1
v0.6.0
v0.6.1
v0.6.2
v0.7.0
v0.7.1
v1.0.0
v1.0.0-alpha
+ 15 more Show less
v1.0.0-beta
v1.0.0-beta2
v1.0.0-rc1
v1.0.0-rc2
v1.0.0-rc3
v1.0.0-rc4
v1.0.0-rc5
v1.0.0-rc6
v1.0.1
v1.0.2
v1.0.3
2.0.2
v2.0.0
v2.0.1
v2.0.3
Fixed in
1.0.4
2.0.4
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
v1.0.0-rc2
pre
2 CVEs
GHSA-gm98-g2wf-7c68
May 15, 2024
amphp/artax Cookie leakage to wrong origins and non-restricted cookie acceptance
Medium
In artax version before 1.0.6 and 2 before 2.0.6, cookies of Affected versions
2.0.2
v2.0.0
v2.0.1
v2.0.3
v2.0.4
v2.0.5
v0.1.0
v0.3.7
v0.4.0
v0.5.0
v0.5.1
v0.6.0
+ 19 more Show less
v0.6.1
v0.6.2
v0.7.0
v0.7.1
v1.0.0
v1.0.0-alpha
v1.0.0-beta
v1.0.0-beta2
v1.0.0-rc1
v1.0.0-rc2
v1.0.0-rc3
v1.0.0-rc4
v1.0.0-rc5
v1.0.0-rc6
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
Fixed in
1.0.6
2.0.6
References
Updated Nov 29, 2024 · Source: OSV.dev
CVE-2016-5385
GHSA-m6ch-gg5f-wxx3
Apr 07, 2022
HTTP Proxy header vulnerability
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
PHP through 7.0.8 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, as demonstrated by (1) an application that makes a getenv('HTTP_PROXY') call or (2) a CGI configuration of PHP, aka an "httpoxy" issue. Affected versions
v0.1.0
v0.3.7
v0.4.0
v0.5.0
v0.5.1
v0.6.0
v0.6.1
v0.6.2
v0.7.0
v0.7.1
v1.0.0
v1.0.0-alpha
+ 15 more Show less
v1.0.0-beta
v1.0.0-beta2
v1.0.0-rc1
v1.0.0-rc2
v1.0.0-rc3
v1.0.0-rc4
v1.0.0-rc5
v1.0.0-rc6
v1.0.1
v1.0.2
v1.0.3
2.0.2
v2.0.0
v2.0.1
v2.0.3
Fixed in
1.0.4
2.0.4
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
v1.0.0-rc1
pre
2 CVEs
GHSA-gm98-g2wf-7c68
May 15, 2024
amphp/artax Cookie leakage to wrong origins and non-restricted cookie acceptance
Medium
In artax version before 1.0.6 and 2 before 2.0.6, cookies of Affected versions
2.0.2
v2.0.0
v2.0.1
v2.0.3
v2.0.4
v2.0.5
v0.1.0
v0.3.7
v0.4.0
v0.5.0
v0.5.1
v0.6.0
+ 19 more Show less
v0.6.1
v0.6.2
v0.7.0
v0.7.1
v1.0.0
v1.0.0-alpha
v1.0.0-beta
v1.0.0-beta2
v1.0.0-rc1
v1.0.0-rc2
v1.0.0-rc3
v1.0.0-rc4
v1.0.0-rc5
v1.0.0-rc6
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
Fixed in
1.0.6
2.0.6
References
Updated Nov 29, 2024 · Source: OSV.dev
CVE-2016-5385
GHSA-m6ch-gg5f-wxx3
Apr 07, 2022
HTTP Proxy header vulnerability
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
PHP through 7.0.8 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, as demonstrated by (1) an application that makes a getenv('HTTP_PROXY') call or (2) a CGI configuration of PHP, aka an "httpoxy" issue. Affected versions
v0.1.0
v0.3.7
v0.4.0
v0.5.0
v0.5.1
v0.6.0
v0.6.1
v0.6.2
v0.7.0
v0.7.1
v1.0.0
v1.0.0-alpha
+ 15 more Show less
v1.0.0-beta
v1.0.0-beta2
v1.0.0-rc1
v1.0.0-rc2
v1.0.0-rc3
v1.0.0-rc4
v1.0.0-rc5
v1.0.0-rc6
v1.0.1
v1.0.2
v1.0.3
2.0.2
v2.0.0
v2.0.1
v2.0.3
Fixed in
1.0.4
2.0.4
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
v1.0.0-beta2
pre
2 CVEs
GHSA-gm98-g2wf-7c68
May 15, 2024
amphp/artax Cookie leakage to wrong origins and non-restricted cookie acceptance
Medium
In artax version before 1.0.6 and 2 before 2.0.6, cookies of Affected versions
2.0.2
v2.0.0
v2.0.1
v2.0.3
v2.0.4
v2.0.5
v0.1.0
v0.3.7
v0.4.0
v0.5.0
v0.5.1
v0.6.0
+ 19 more Show less
v0.6.1
v0.6.2
v0.7.0
v0.7.1
v1.0.0
v1.0.0-alpha
v1.0.0-beta
v1.0.0-beta2
v1.0.0-rc1
v1.0.0-rc2
v1.0.0-rc3
v1.0.0-rc4
v1.0.0-rc5
v1.0.0-rc6
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
Fixed in
1.0.6
2.0.6
References
Updated Nov 29, 2024 · Source: OSV.dev
CVE-2016-5385
GHSA-m6ch-gg5f-wxx3
Apr 07, 2022
HTTP Proxy header vulnerability
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
PHP through 7.0.8 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, as demonstrated by (1) an application that makes a getenv('HTTP_PROXY') call or (2) a CGI configuration of PHP, aka an "httpoxy" issue. Affected versions
v0.1.0
v0.3.7
v0.4.0
v0.5.0
v0.5.1
v0.6.0
v0.6.1
v0.6.2
v0.7.0
v0.7.1
v1.0.0
v1.0.0-alpha
+ 15 more Show less
v1.0.0-beta
v1.0.0-beta2
v1.0.0-rc1
v1.0.0-rc2
v1.0.0-rc3
v1.0.0-rc4
v1.0.0-rc5
v1.0.0-rc6
v1.0.1
v1.0.2
v1.0.3
2.0.2
v2.0.0
v2.0.1
v2.0.3
Fixed in
1.0.4
2.0.4
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
v1.0.0-beta
pre
2 CVEs
GHSA-gm98-g2wf-7c68
May 15, 2024
amphp/artax Cookie leakage to wrong origins and non-restricted cookie acceptance
Medium
In artax version before 1.0.6 and 2 before 2.0.6, cookies of Affected versions
2.0.2
v2.0.0
v2.0.1
v2.0.3
v2.0.4
v2.0.5
v0.1.0
v0.3.7
v0.4.0
v0.5.0
v0.5.1
v0.6.0
+ 19 more Show less
v0.6.1
v0.6.2
v0.7.0
v0.7.1
v1.0.0
v1.0.0-alpha
v1.0.0-beta
v1.0.0-beta2
v1.0.0-rc1
v1.0.0-rc2
v1.0.0-rc3
v1.0.0-rc4
v1.0.0-rc5
v1.0.0-rc6
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
Fixed in
1.0.6
2.0.6
References
Updated Nov 29, 2024 · Source: OSV.dev
CVE-2016-5385
GHSA-m6ch-gg5f-wxx3
Apr 07, 2022
HTTP Proxy header vulnerability
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
PHP through 7.0.8 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, as demonstrated by (1) an application that makes a getenv('HTTP_PROXY') call or (2) a CGI configuration of PHP, aka an "httpoxy" issue. Affected versions
v0.1.0
v0.3.7
v0.4.0
v0.5.0
v0.5.1
v0.6.0
v0.6.1
v0.6.2
v0.7.0
v0.7.1
v1.0.0
v1.0.0-alpha
+ 15 more Show less
v1.0.0-beta
v1.0.0-beta2
v1.0.0-rc1
v1.0.0-rc2
v1.0.0-rc3
v1.0.0-rc4
v1.0.0-rc5
v1.0.0-rc6
v1.0.1
v1.0.2
v1.0.3
2.0.2
v2.0.0
v2.0.1
v2.0.3
Fixed in
1.0.4
2.0.4
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
v1.0.0-alpha
pre
2 CVEs
GHSA-gm98-g2wf-7c68
May 15, 2024
amphp/artax Cookie leakage to wrong origins and non-restricted cookie acceptance
Medium
In artax version before 1.0.6 and 2 before 2.0.6, cookies of Affected versions
2.0.2
v2.0.0
v2.0.1
v2.0.3
v2.0.4
v2.0.5
v0.1.0
v0.3.7
v0.4.0
v0.5.0
v0.5.1
v0.6.0
+ 19 more Show less
v0.6.1
v0.6.2
v0.7.0
v0.7.1
v1.0.0
v1.0.0-alpha
v1.0.0-beta
v1.0.0-beta2
v1.0.0-rc1
v1.0.0-rc2
v1.0.0-rc3
v1.0.0-rc4
v1.0.0-rc5
v1.0.0-rc6
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
Fixed in
1.0.6
2.0.6
References
Updated Nov 29, 2024 · Source: OSV.dev
CVE-2016-5385
GHSA-m6ch-gg5f-wxx3
Apr 07, 2022
HTTP Proxy header vulnerability
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
PHP through 7.0.8 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, as demonstrated by (1) an application that makes a getenv('HTTP_PROXY') call or (2) a CGI configuration of PHP, aka an "httpoxy" issue. Affected versions
v0.1.0
v0.3.7
v0.4.0
v0.5.0
v0.5.1
v0.6.0
v0.6.1
v0.6.2
v0.7.0
v0.7.1
v1.0.0
v1.0.0-alpha
+ 15 more Show less
v1.0.0-beta
v1.0.0-beta2
v1.0.0-rc1
v1.0.0-rc2
v1.0.0-rc3
v1.0.0-rc4
v1.0.0-rc5
v1.0.0-rc6
v1.0.1
v1.0.2
v1.0.3
2.0.2
v2.0.0
v2.0.1
v2.0.3
Fixed in
1.0.4
2.0.4
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
v0.7.1
patch
2 CVEs
GHSA-gm98-g2wf-7c68
May 15, 2024
amphp/artax Cookie leakage to wrong origins and non-restricted cookie acceptance
Medium
In artax version before 1.0.6 and 2 before 2.0.6, cookies of Affected versions
2.0.2
v2.0.0
v2.0.1
v2.0.3
v2.0.4
v2.0.5
v0.1.0
v0.3.7
v0.4.0
v0.5.0
v0.5.1
v0.6.0
+ 19 more Show less
v0.6.1
v0.6.2
v0.7.0
v0.7.1
v1.0.0
v1.0.0-alpha
v1.0.0-beta
v1.0.0-beta2
v1.0.0-rc1
v1.0.0-rc2
v1.0.0-rc3
v1.0.0-rc4
v1.0.0-rc5
v1.0.0-rc6
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
Fixed in
1.0.6
2.0.6
References
Updated Nov 29, 2024 · Source: OSV.dev
CVE-2016-5385
GHSA-m6ch-gg5f-wxx3
Apr 07, 2022
HTTP Proxy header vulnerability
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
PHP through 7.0.8 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, as demonstrated by (1) an application that makes a getenv('HTTP_PROXY') call or (2) a CGI configuration of PHP, aka an "httpoxy" issue. Affected versions
v0.1.0
v0.3.7
v0.4.0
v0.5.0
v0.5.1
v0.6.0
v0.6.1
v0.6.2
v0.7.0
v0.7.1
v1.0.0
v1.0.0-alpha
+ 15 more Show less
v1.0.0-beta
v1.0.0-beta2
v1.0.0-rc1
v1.0.0-rc2
v1.0.0-rc3
v1.0.0-rc4
v1.0.0-rc5
v1.0.0-rc6
v1.0.1
v1.0.2
v1.0.3
2.0.2
v2.0.0
v2.0.1
v2.0.3
Fixed in
1.0.4
2.0.4
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
v0.7.0
minor
2 CVEs
GHSA-gm98-g2wf-7c68
May 15, 2024
amphp/artax Cookie leakage to wrong origins and non-restricted cookie acceptance
Medium
In artax version before 1.0.6 and 2 before 2.0.6, cookies of Affected versions
2.0.2
v2.0.0
v2.0.1
v2.0.3
v2.0.4
v2.0.5
v0.1.0
v0.3.7
v0.4.0
v0.5.0
v0.5.1
v0.6.0
+ 19 more Show less
v0.6.1
v0.6.2
v0.7.0
v0.7.1
v1.0.0
v1.0.0-alpha
v1.0.0-beta
v1.0.0-beta2
v1.0.0-rc1
v1.0.0-rc2
v1.0.0-rc3
v1.0.0-rc4
v1.0.0-rc5
v1.0.0-rc6
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
Fixed in
1.0.6
2.0.6
References
Updated Nov 29, 2024 · Source: OSV.dev
CVE-2016-5385
GHSA-m6ch-gg5f-wxx3
Apr 07, 2022
HTTP Proxy header vulnerability
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
PHP through 7.0.8 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, as demonstrated by (1) an application that makes a getenv('HTTP_PROXY') call or (2) a CGI configuration of PHP, aka an "httpoxy" issue. Affected versions
v0.1.0
v0.3.7
v0.4.0
v0.5.0
v0.5.1
v0.6.0
v0.6.1
v0.6.2
v0.7.0
v0.7.1
v1.0.0
v1.0.0-alpha
+ 15 more Show less
v1.0.0-beta
v1.0.0-beta2
v1.0.0-rc1
v1.0.0-rc2
v1.0.0-rc3
v1.0.0-rc4
v1.0.0-rc5
v1.0.0-rc6
v1.0.1
v1.0.2
v1.0.3
2.0.2
v2.0.0
v2.0.1
v2.0.3
Fixed in
1.0.4
2.0.4
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
v0.6.2
patch
2 CVEs
GHSA-gm98-g2wf-7c68
May 15, 2024
amphp/artax Cookie leakage to wrong origins and non-restricted cookie acceptance
Medium
In artax version before 1.0.6 and 2 before 2.0.6, cookies of Affected versions
2.0.2
v2.0.0
v2.0.1
v2.0.3
v2.0.4
v2.0.5
v0.1.0
v0.3.7
v0.4.0
v0.5.0
v0.5.1
v0.6.0
+ 19 more Show less
v0.6.1
v0.6.2
v0.7.0
v0.7.1
v1.0.0
v1.0.0-alpha
v1.0.0-beta
v1.0.0-beta2
v1.0.0-rc1
v1.0.0-rc2
v1.0.0-rc3
v1.0.0-rc4
v1.0.0-rc5
v1.0.0-rc6
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
Fixed in
1.0.6
2.0.6
References
Updated Nov 29, 2024 · Source: OSV.dev
CVE-2016-5385
GHSA-m6ch-gg5f-wxx3
Apr 07, 2022
HTTP Proxy header vulnerability
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
PHP through 7.0.8 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, as demonstrated by (1) an application that makes a getenv('HTTP_PROXY') call or (2) a CGI configuration of PHP, aka an "httpoxy" issue. Affected versions
v0.1.0
v0.3.7
v0.4.0
v0.5.0
v0.5.1
v0.6.0
v0.6.1
v0.6.2
v0.7.0
v0.7.1
v1.0.0
v1.0.0-alpha
+ 15 more Show less
v1.0.0-beta
v1.0.0-beta2
v1.0.0-rc1
v1.0.0-rc2
v1.0.0-rc3
v1.0.0-rc4
v1.0.0-rc5
v1.0.0-rc6
v1.0.1
v1.0.2
v1.0.3
2.0.2
v2.0.0
v2.0.1
v2.0.3
Fixed in
1.0.4
2.0.4
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
v0.6.1
patch
2 CVEs
GHSA-gm98-g2wf-7c68
May 15, 2024
amphp/artax Cookie leakage to wrong origins and non-restricted cookie acceptance
Medium
In artax version before 1.0.6 and 2 before 2.0.6, cookies of Affected versions
2.0.2
v2.0.0
v2.0.1
v2.0.3
v2.0.4
v2.0.5
v0.1.0
v0.3.7
v0.4.0
v0.5.0
v0.5.1
v0.6.0
+ 19 more Show less
v0.6.1
v0.6.2
v0.7.0
v0.7.1
v1.0.0
v1.0.0-alpha
v1.0.0-beta
v1.0.0-beta2
v1.0.0-rc1
v1.0.0-rc2
v1.0.0-rc3
v1.0.0-rc4
v1.0.0-rc5
v1.0.0-rc6
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
Fixed in
1.0.6
2.0.6
References
Updated Nov 29, 2024 · Source: OSV.dev
CVE-2016-5385
GHSA-m6ch-gg5f-wxx3
Apr 07, 2022
HTTP Proxy header vulnerability
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
PHP through 7.0.8 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, as demonstrated by (1) an application that makes a getenv('HTTP_PROXY') call or (2) a CGI configuration of PHP, aka an "httpoxy" issue. Affected versions
v0.1.0
v0.3.7
v0.4.0
v0.5.0
v0.5.1
v0.6.0
v0.6.1
v0.6.2
v0.7.0
v0.7.1
v1.0.0
v1.0.0-alpha
+ 15 more Show less
v1.0.0-beta
v1.0.0-beta2
v1.0.0-rc1
v1.0.0-rc2
v1.0.0-rc3
v1.0.0-rc4
v1.0.0-rc5
v1.0.0-rc6
v1.0.1
v1.0.2
v1.0.3
2.0.2
v2.0.0
v2.0.1
v2.0.3
Fixed in
1.0.4
2.0.4
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
v0.6.0
minor
2 CVEs
GHSA-gm98-g2wf-7c68
May 15, 2024
amphp/artax Cookie leakage to wrong origins and non-restricted cookie acceptance
Medium
In artax version before 1.0.6 and 2 before 2.0.6, cookies of Affected versions
2.0.2
v2.0.0
v2.0.1
v2.0.3
v2.0.4
v2.0.5
v0.1.0
v0.3.7
v0.4.0
v0.5.0
v0.5.1
v0.6.0
+ 19 more Show less
v0.6.1
v0.6.2
v0.7.0
v0.7.1
v1.0.0
v1.0.0-alpha
v1.0.0-beta
v1.0.0-beta2
v1.0.0-rc1
v1.0.0-rc2
v1.0.0-rc3
v1.0.0-rc4
v1.0.0-rc5
v1.0.0-rc6
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
Fixed in
1.0.6
2.0.6
References
Updated Nov 29, 2024 · Source: OSV.dev
CVE-2016-5385
GHSA-m6ch-gg5f-wxx3
Apr 07, 2022
HTTP Proxy header vulnerability
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
PHP through 7.0.8 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, as demonstrated by (1) an application that makes a getenv('HTTP_PROXY') call or (2) a CGI configuration of PHP, aka an "httpoxy" issue. Affected versions
v0.1.0
v0.3.7
v0.4.0
v0.5.0
v0.5.1
v0.6.0
v0.6.1
v0.6.2
v0.7.0
v0.7.1
v1.0.0
v1.0.0-alpha
+ 15 more Show less
v1.0.0-beta
v1.0.0-beta2
v1.0.0-rc1
v1.0.0-rc2
v1.0.0-rc3
v1.0.0-rc4
v1.0.0-rc5
v1.0.0-rc6
v1.0.1
v1.0.2
v1.0.3
2.0.2
v2.0.0
v2.0.1
v2.0.3
Fixed in
1.0.4
2.0.4
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
v0.5.1
patch
2 CVEs
GHSA-gm98-g2wf-7c68
May 15, 2024
amphp/artax Cookie leakage to wrong origins and non-restricted cookie acceptance
Medium
In artax version before 1.0.6 and 2 before 2.0.6, cookies of Affected versions
2.0.2
v2.0.0
v2.0.1
v2.0.3
v2.0.4
v2.0.5
v0.1.0
v0.3.7
v0.4.0
v0.5.0
v0.5.1
v0.6.0
+ 19 more Show less
v0.6.1
v0.6.2
v0.7.0
v0.7.1
v1.0.0
v1.0.0-alpha
v1.0.0-beta
v1.0.0-beta2
v1.0.0-rc1
v1.0.0-rc2
v1.0.0-rc3
v1.0.0-rc4
v1.0.0-rc5
v1.0.0-rc6
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
Fixed in
1.0.6
2.0.6
References
Updated Nov 29, 2024 · Source: OSV.dev
CVE-2016-5385
GHSA-m6ch-gg5f-wxx3
Apr 07, 2022
HTTP Proxy header vulnerability
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
PHP through 7.0.8 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, as demonstrated by (1) an application that makes a getenv('HTTP_PROXY') call or (2) a CGI configuration of PHP, aka an "httpoxy" issue. Affected versions
v0.1.0
v0.3.7
v0.4.0
v0.5.0
v0.5.1
v0.6.0
v0.6.1
v0.6.2
v0.7.0
v0.7.1
v1.0.0
v1.0.0-alpha
+ 15 more Show less
v1.0.0-beta
v1.0.0-beta2
v1.0.0-rc1
v1.0.0-rc2
v1.0.0-rc3
v1.0.0-rc4
v1.0.0-rc5
v1.0.0-rc6
v1.0.1
v1.0.2
v1.0.3
2.0.2
v2.0.0
v2.0.1
v2.0.3
Fixed in
1.0.4
2.0.4
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
v0.5.0
minor
2 CVEs
GHSA-gm98-g2wf-7c68
May 15, 2024
amphp/artax Cookie leakage to wrong origins and non-restricted cookie acceptance
Medium
In artax version before 1.0.6 and 2 before 2.0.6, cookies of Affected versions
2.0.2
v2.0.0
v2.0.1
v2.0.3
v2.0.4
v2.0.5
v0.1.0
v0.3.7
v0.4.0
v0.5.0
v0.5.1
v0.6.0
+ 19 more Show less
v0.6.1
v0.6.2
v0.7.0
v0.7.1
v1.0.0
v1.0.0-alpha
v1.0.0-beta
v1.0.0-beta2
v1.0.0-rc1
v1.0.0-rc2
v1.0.0-rc3
v1.0.0-rc4
v1.0.0-rc5
v1.0.0-rc6
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
Fixed in
1.0.6
2.0.6
References
Updated Nov 29, 2024 · Source: OSV.dev
CVE-2016-5385
GHSA-m6ch-gg5f-wxx3
Apr 07, 2022
HTTP Proxy header vulnerability
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
PHP through 7.0.8 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, as demonstrated by (1) an application that makes a getenv('HTTP_PROXY') call or (2) a CGI configuration of PHP, aka an "httpoxy" issue. Affected versions
v0.1.0
v0.3.7
v0.4.0
v0.5.0
v0.5.1
v0.6.0
v0.6.1
v0.6.2
v0.7.0
v0.7.1
v1.0.0
v1.0.0-alpha
+ 15 more Show less
v1.0.0-beta
v1.0.0-beta2
v1.0.0-rc1
v1.0.0-rc2
v1.0.0-rc3
v1.0.0-rc4
v1.0.0-rc5
v1.0.0-rc6
v1.0.1
v1.0.2
v1.0.3
2.0.2
v2.0.0
v2.0.1
v2.0.3
Fixed in
1.0.4
2.0.4
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
v0.4.0
minor
2 CVEs
GHSA-gm98-g2wf-7c68
May 15, 2024
amphp/artax Cookie leakage to wrong origins and non-restricted cookie acceptance
Medium
In artax version before 1.0.6 and 2 before 2.0.6, cookies of Affected versions
2.0.2
v2.0.0
v2.0.1
v2.0.3
v2.0.4
v2.0.5
v0.1.0
v0.3.7
v0.4.0
v0.5.0
v0.5.1
v0.6.0
+ 19 more Show less
v0.6.1
v0.6.2
v0.7.0
v0.7.1
v1.0.0
v1.0.0-alpha
v1.0.0-beta
v1.0.0-beta2
v1.0.0-rc1
v1.0.0-rc2
v1.0.0-rc3
v1.0.0-rc4
v1.0.0-rc5
v1.0.0-rc6
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
Fixed in
1.0.6
2.0.6
References
Updated Nov 29, 2024 · Source: OSV.dev
CVE-2016-5385
GHSA-m6ch-gg5f-wxx3
Apr 07, 2022
HTTP Proxy header vulnerability
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
PHP through 7.0.8 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, as demonstrated by (1) an application that makes a getenv('HTTP_PROXY') call or (2) a CGI configuration of PHP, aka an "httpoxy" issue. Affected versions
v0.1.0
v0.3.7
v0.4.0
v0.5.0
v0.5.1
v0.6.0
v0.6.1
v0.6.2
v0.7.0
v0.7.1
v1.0.0
v1.0.0-alpha
+ 15 more Show less
v1.0.0-beta
v1.0.0-beta2
v1.0.0-rc1
v1.0.0-rc2
v1.0.0-rc3
v1.0.0-rc4
v1.0.0-rc5
v1.0.0-rc6
v1.0.1
v1.0.2
v1.0.3
2.0.2
v2.0.0
v2.0.1
v2.0.3
Fixed in
1.0.4
2.0.4
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
v0.3.7
minor
2 CVEs
GHSA-gm98-g2wf-7c68
May 15, 2024
amphp/artax Cookie leakage to wrong origins and non-restricted cookie acceptance
Medium
In artax version before 1.0.6 and 2 before 2.0.6, cookies of Affected versions
2.0.2
v2.0.0
v2.0.1
v2.0.3
v2.0.4
v2.0.5
v0.1.0
v0.3.7
v0.4.0
v0.5.0
v0.5.1
v0.6.0
+ 19 more Show less
v0.6.1
v0.6.2
v0.7.0
v0.7.1
v1.0.0
v1.0.0-alpha
v1.0.0-beta
v1.0.0-beta2
v1.0.0-rc1
v1.0.0-rc2
v1.0.0-rc3
v1.0.0-rc4
v1.0.0-rc5
v1.0.0-rc6
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
Fixed in
1.0.6
2.0.6
References
Updated Nov 29, 2024 · Source: OSV.dev
CVE-2016-5385
GHSA-m6ch-gg5f-wxx3
Apr 07, 2022
HTTP Proxy header vulnerability
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
PHP through 7.0.8 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, as demonstrated by (1) an application that makes a getenv('HTTP_PROXY') call or (2) a CGI configuration of PHP, aka an "httpoxy" issue. Affected versions
v0.1.0
v0.3.7
v0.4.0
v0.5.0
v0.5.1
v0.6.0
v0.6.1
v0.6.2
v0.7.0
v0.7.1
v1.0.0
v1.0.0-alpha
+ 15 more Show less
v1.0.0-beta
v1.0.0-beta2
v1.0.0-rc1
v1.0.0-rc2
v1.0.0-rc3
v1.0.0-rc4
v1.0.0-rc5
v1.0.0-rc6
v1.0.1
v1.0.2
v1.0.3
2.0.2
v2.0.0
v2.0.1
v2.0.3
Fixed in
1.0.4
2.0.4
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
v0.1.0
initial
2 CVEs
GHSA-gm98-g2wf-7c68
May 15, 2024
amphp/artax Cookie leakage to wrong origins and non-restricted cookie acceptance
Medium
In artax version before 1.0.6 and 2 before 2.0.6, cookies of Affected versions
2.0.2
v2.0.0
v2.0.1
v2.0.3
v2.0.4
v2.0.5
v0.1.0
v0.3.7
v0.4.0
v0.5.0
v0.5.1
v0.6.0
+ 19 more Show less
v0.6.1
v0.6.2
v0.7.0
v0.7.1
v1.0.0
v1.0.0-alpha
v1.0.0-beta
v1.0.0-beta2
v1.0.0-rc1
v1.0.0-rc2
v1.0.0-rc3
v1.0.0-rc4
v1.0.0-rc5
v1.0.0-rc6
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
Fixed in
1.0.6
2.0.6
References
Updated Nov 29, 2024 · Source: OSV.dev
CVE-2016-5385
GHSA-m6ch-gg5f-wxx3
Apr 07, 2022
HTTP Proxy header vulnerability
8.1
/ 10
High
Network
High
None
None
Unchanged
High
High
High
PHP through 7.0.8 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, as demonstrated by (1) an application that makes a getenv('HTTP_PROXY') call or (2) a CGI configuration of PHP, aka an "httpoxy" issue. Affected versions
v0.1.0
v0.3.7
v0.4.0
v0.5.0
v0.5.1
v0.6.0
v0.6.1
v0.6.2
v0.7.0
v0.7.1
v1.0.0
v1.0.0-alpha
+ 15 more Show less
v1.0.0-beta
v1.0.0-beta2
v1.0.0-rc1
v1.0.0-rc2
v1.0.0-rc3
v1.0.0-rc4
v1.0.0-rc5
v1.0.0-rc6
v1.0.1
v1.0.2
v1.0.3
2.0.2
v2.0.0
v2.0.1
v2.0.3
Fixed in
1.0.4
2.0.4
References
Updated Nov 08, 2023 · Source: OSV.dev |