Skip to main content
MEDIUM

CVE-2020-7070

CVSS v3

5.3

MEDIUM

EPSS Score

26.1 %

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

In PHP versions 7.2.x below 7.2.34, 7.3.x below 7.3.23 and 7.4.x below 7.4.11, when PHP is processing incoming HTTP cookie values, the cookie names are url-decoded. This may lead to cookies with prefixes like __Host confused with cookies that decode to such prefix, thus leading to an attacker being able to forge cookie which is supposed to be secure. See also CVE-2020-8184 for more information.

Technical details

Published
2020-10-02

Frequently asked questions

What is CVE-2020-7070?

In PHP versions 7.2.x below 7.2.34, 7.3.x below 7.3.23 and 7.4.x below 7.4.11, when PHP is processing incoming HTTP cookie values, the cookie names are url-decoded. This may lead to cookies with prefixes like __Host confused with cookies that decode to such prefix, thus leading to an attacker being able to forge cookie which is supposed to be secure. See also CVE-2020-8184 for more information.

Is CVE-2020-7070 actively exploited?

Active exploitation of CVE-2020-7070 has not been confirmed. The EPSS score is 26.1%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2020-7070?

CVE-2020-7070 has a CVSS v3 base score of 5.3 (MEDIUM severity).

Is CVE-2020-7070 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 500 free checks/month · Free API key