CVE-2014-8684
CodeIgniter and Kohana vulnerable to PHP Object Injection
9.8
CRITICAL
CVSS 3.1
EPSS 71.5%
Description
CodeIgniter before 3.0 and Kohana 3.2.3 and earlier and 3.3.x through 3.3.2 make it easier for remote attackers to spoof session cookies and consequently conduct PHP object injection attacks by leveraging use of standard string comparison operators to compare cryptographic hashes.
How to fix CVE-2014-8684
To remediate CVE-2014-8684, upgrade the affected package to a fixed version below.
- —upgrade to 3.0.0 or later
- —upgrade to 3.3.3 or later
Is CVE-2014-8684 being exploited?
Likely — EPSS is 71.5%, placing CVE-2014-8684 in the top tier of vulnerabilities by exploitation probability. Prioritise patching.
Affected packages (2)
- from 0, < 3.0.0
- from 0, < 3.3.3
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | CRITICAL9.8 | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |