Skip to main content
HIGH

CVE-2023-3823

CVSS v3

7.5

HIGH

EPSS Score

0.3 %

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

In PHP versions 8.0.* before 8.0.30, 8.1.* before 8.1.22, and 8.2.* before 8.2.8 various XML functions rely on libxml global state to track configuration variables, like whether external entities are loaded. This state is assumed to be unchanged unless the user explicitly changes it by calling appropriate function. However, since the state is process-global, other modules - such as ImageMagick - may also use this library within the same process, and change that global state for their internal purposes, and leave it in a state where external entities loading is enabled. This can lead to the situation where external XML is parsed with external entities loaded, which can lead to disclosure of any local files accessible to PHP. This vulnerable state may persist in the same process across many requests, until the process is shut down.

Technical details

Published
2023-08-11

Frequently asked questions

What is CVE-2023-3823?

In PHP versions 8.0.* before 8.0.30, 8.1.* before 8.1.22, and 8.2.* before 8.2.8 various XML functions rely on libxml global state to track configuration variables, like whether external entities are loaded. This state is assumed to be unchanged unless the user explicitly changes it by calling appropriate function. However, since the state is process-global, other modules - such as ImageMagick - may also use this library within the same process, and change that global state for their internal purposes, and leave it in a state where external entities loading is enabled. This can lead to the situation where external XML is parsed with external entities loaded, which can lead to disclosure of any local files accessible to PHP. This vulnerable state may persist in the same process across many requests, until the process is shut down.

Is CVE-2023-3823 actively exploited?

Active exploitation of CVE-2023-3823 has not been confirmed. The EPSS score is 0.3%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2023-3823?

CVE-2023-3823 has a CVSS v3 base score of 7.5 (HIGH severity).

Is CVE-2023-3823 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 500 free checks/month · Free API key