CVE-2024-8927
In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, HTTP_REDIRECT_STATUS variable is used to check whether or not CGI binary is being run by the HTTP server. However, in certain scenarios, the content of this variable can be controlled by the request submitter via HTTP headers, which can lead to cgi.force_redirect option not being correctly applied. In certain configurations this may lead to arbitrary file inclusion in PHP.
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Base score: 7.5
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 1.05%
- Percentile among all scored CVEs: 63
- Score date: 10/10/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
🎯 ATT&CK techniques
How this vulnerability is exploited and what the attacker gains, in MITRE ATT&CK terms.
- Exploitation
T1190Exploit Public-Facing Applicationinitial access95 % - Primary impact
T1005Data from Local Systemcollection85 %
Vulnerabilidad remota en PHP (AV:N, PR:N, UI:N) que permite eludir protecciones CGI mediante headers HTTP controlables, resultando en inclusión arbitraria de archivos y lectura de datos sensibles.
Inferred by our analysis agent from the official description, CVSS vector and CWE, and checked by a supervisor. May contain errors.
🛡️ ATT&CK mitigations that cover these techniques
Affected technologies (1)
CWEs
- NVD-CWE-Other
- CWE-1220
References
Raw JSON (NVD)
Show
{
"id": "CVE-2024-8927",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-8927",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2024-10-08T12:50:40.800289Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security@php.net",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 3.9
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "security@php.net",
"affectedData": [
{
"vendor": "PHP Group",
"product": "PHP",
"versions": [
{
"status": "affected",
"version": "8.1.*",
"lessThan": "8.1.30",
"versionType": "semver"
},
{
"status": "affected",
"version": "8.2.*",
"lessThan": "8.2.24",
"versionType": "semver"
},
{
"status": "affected",
"version": "8.3.*",
"lessThan": "8.3.12",
"versionType": "semver"
}
],
"defaultStatus": "unaffected"
}
]
},
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"affectedData": [
{
"cpes": [
"cpe:2.3:a:php:php:*:*:*:*:*:*:*:*"
],
"vendor": "php",
"product": "php",
"versions": [
{
"status": "affected",
"version": "8.1.0",
"lessThan": "8.1.30",
"versionType": "semver"
},
{
"status": "affected",
"version": "8.2.0",
"lessThan": "8.2.24",
"versionType": "semver"
},
{
"status": "affected",
"version": "8.3.0",
"lessThan": "8.3.12",
"versionType": "semver"
}
],
"defaultStatus": "unknown"
}
]
}
],
"published": "2024-10-08T04:15:10.867",
"references": [
{
"url": "https://github.com/php/php-src/security/advisories/GHSA-94p6-54jq-9mwp",
"tags": [
"Exploit",
"Vendor Advisory"
],
"source": "security@php.net"
},
{
"url": "https://lists.debian.org/debian-lts-announce/2024/10/msg00011.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://security.netapp.com/advisory/ntap-20241101-0003/",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
},
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"description": [
{
"lang": "en",
"value": "CWE-1220"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, HTTP_REDIRECT_STATUS variable is used to check whether or not CGI binary is being run by the HTTP server. However, in certain scenarios, the content of this variable can be controlled by the request submitter via HTTP headers, which can lead to cgi.force_redirect option not being correctly applied. In certain configurations this may lead to arbitrary file inclusion in PHP."
},
{
"lang": "es",
"value": "En las versiones de PHP 8.1.* anteriores a 8.1.30, 8.2.* anteriores a 8.2.24, 8.3.* anteriores a 8.3.12, la variable HTTP_REDIRECT_STATUS se utiliza para comprobar si el servidor HTTP está ejecutando o no el binario CGI. Sin embargo, en determinados escenarios, el remitente de la solicitud puede controlar el contenido de esta variable a través de los encabezados HTTP, lo que puede provocar que la opción cgi.force_redirect no se aplique correctamente. En determinadas configuraciones, esto puede provocar la inclusión arbitraria de archivos en PHP."
}
],
"lastModified": "2026-06-17T08:23:34.680",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:php:php:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0AE1547D-26D1-4BD3-9EF8-B0E61BB7FFCB",
"versionEndExcluding": "8.1.30",
"versionStartIncluding": "8.1.0"
},
{
"criteria": "cpe:2.3:a:php:php:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "01D71D50-4234-4537-984F-DB2A675EDA24",
"versionEndExcluding": "8.2.24",
"versionStartIncluding": "8.2.0"
},
{
"criteria": "cpe:2.3:a:php:php:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3236DC72-ADB3-44C3-8A19-4EC37B9FFDD7",
"versionEndExcluding": "8.3.12",
"versionStartIncluding": "8.3.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security@php.net"
}