CVE Database
/

CVE-2022-36937

Back to search

CVE-2022-36937

Published: May 10, 2023

Modified: Jan 27, 2025

PUBLISHED

Description

HHVM 4.172.0 and all prior versions use TLS 1.0 for secure connections when handling tls:// URLs in the stream extension. TLS1.0 has numerous published vulnerabilities and is deprecated. HHVM 4.153.4, 4.168.2, 4.169.2, 4.170.2, 4.171.1, 4.172.1, 4.173.0 replaces TLS1.0 with TLS1.3. Applications that call stream_socket_server or stream_socket_client functions with a URL starting with tls:// are affected.

VendorProductVersions

Facebook

HHVM

affected
4.172.0 - < 4.172.1
affected
4.171.0 - < 4.171.1
affected
4.170.0 - < 4.170.2
affected
4.169.0 - < 4.169.2
affected
4.154.0 - < 1.168.2

+1 more versions

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now
CVE-2022-36937 - Security Vulnerability | QwikSec