CVE-2022-31042 is a high-severity information disclosure vulnerability in Guzzle, an open-source PHP HTTP client, affecting versions prior to 6.5.7 and 7.4.4. It allows sensitive Cookie headers to be forwarded during redirects from HTTPS to HTTP, or to different hosts, potentially exposing user session information. With a CVSS score of 7.5, this vulnerability has a low attack complexity and no user interaction required, leading to a high confidentiality impact. While no public exploit code or active exploitation has been confirmed, it has garnered some community discussion and media coverage, including a SecurityWeek article highlighting its impact on Drupal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 6.5.7CPE matchmatch criteria | cpe:2.3:a:guzzlephp:guzzle:*:*:*:*:*:*:*:* | ||
>= 7.0.0, < 7.4.4CPE matchmatch criteria | cpe:2.3:a:guzzlephp:guzzle:*:*:*:*:*:*:*:* | ||
>= 9.2.0, < 9.2.21CPE matchmatch criteria | cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:* | ||
>= 9.3.0, < 9.3.16CPE matchmatch criteria | cpe:2.3:a:drupal:drupal:*:*:*:*:*:*:*:* | ||
9.4.0CPE matchmatch criteria | cpe:2.3:a:drupal:drupal:9.4.0:alpha1:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.