CVE-2019-3569

HHVM, when used with FastCGI, would bind by default to all available interfaces. This behavior could allow a malicious individual unintended direct access to the application, which could result in information disclosure. This issue affects versions 4.3.0, 4.4.0, 4.5.0, 4.6.0, 4.7.0, 4.8.0, versions 3.30.5 and below, and all versions in the 4.0, 4.1, and 4.2 series.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:facebook:hhvm:*:*:*:*:*:*:*:*
cpe:2.3:a:facebook:hhvm:4.0.0:*:*:*:*:*:*:*
cpe:2.3:a:facebook:hhvm:4.0.1:*:*:*:*:*:*:*
cpe:2.3:a:facebook:hhvm:4.0.2:*:*:*:*:*:*:*
cpe:2.3:a:facebook:hhvm:4.0.3:*:*:*:*:*:*:*
cpe:2.3:a:facebook:hhvm:4.0.4:*:*:*:*:*:*:*
cpe:2.3:a:facebook:hhvm:4.1.0:*:*:*:*:*:*:*
cpe:2.3:a:facebook:hhvm:4.2.0:*:*:*:*:*:*:*
cpe:2.3:a:facebook:hhvm:4.3.0:*:*:*:*:*:*:*
cpe:2.3:a:facebook:hhvm:4.4.0:*:*:*:*:*:*:*
cpe:2.3:a:facebook:hhvm:4.5.0:*:*:*:*:*:*:*
cpe:2.3:a:facebook:hhvm:4.6.0:*:*:*:*:*:*:*
cpe:2.3:a:facebook:hhvm:4.7.0:*:*:*:*:*:*:*
cpe:2.3:a:facebook:hhvm:4.8.0:*:*:*:*:*:*:*

History

14 Sep 2021, 12:19

Type Values Removed Values Added
CWE CWE-200 CWE-668

Information

Published : 2019-06-26 15:15

Updated : 2023-12-10 12:59


NVD link : CVE-2019-3569

Mitre link : CVE-2019-3569

CVE.ORG link : CVE-2019-3569


JSON object : View

Products Affected

facebook

  • hhvm
CWE
CWE-668

Exposure of Resource to Wrong Sphere

CWE-552

Files or Directories Accessible to External Parties