CVE-2022-36937
Published: May 10, 2023
Modified: Jan 27, 2025
Description
HHVM 4.172.0 and all prior versions use TLS 1.0 for secure connections when handling tls:// URLs in the stream extension. TLS1.0 has numerous published vulnerabilities and is deprecated. HHVM 4.153.4, 4.168.2, 4.169.2, 4.170.2, 4.171.1, 4.172.1, 4.173.0 replaces TLS1.0 with TLS1.3. Applications that call stream_socket_server or stream_socket_client functions with a URL starting with tls:// are affected.
| Vendor | Product | Versions |
|---|---|---|
HHVM | affected 4.172.0 - < 4.172.1affected 4.171.0 - < 4.171.1affected 4.170.0 - < 4.170.2affected 4.169.0 - < 4.169.2affected 4.154.0 - < 1.168.2+1 more versions |
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now