AZL-27962

    Dashboard / Vulnerabilities / AZL-27962

    AZL-27962

    Published: 11 Aug 2023Last Modified: 21 Apr 2026
    Upstream:

    Summary: CVE-2023-3823 affecting package php for versions less than 8.1.22-1

    Details: In PHP versions 8.0.* before 8.0.30, 8.1.* before 8.1.22, and 8.2.* before 8.2.8 various XML functions rely on libxml global state to track configuration variables, like whether external entities are loaded. This state is assumed to be unchanged unless the user explicitly changes it by calling appropriate function. However, since the state is process-global, other modules - such as ImageMagick - may also use this library within the same process, and change that global state for their internal purposes, and leave it in a state where external entities loading is enabled. This can lead to the situation where external XML is parsed with external entities loaded, which can lead to disclosure of any local files accessible to PHP. This vulnerable state may persist in the same process across many requests, until the process is shut down.

    Affected packages

    Package

    Name: php

    Purl: pkg:rpm/azure-linux/php

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -8.1.22-1

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    AZL-27962 | CVE-DB