---
cve: "CVE-2024-8929"
severity: "MEDIUM"
cvss: 5.8
epss: "2.3%"
vendor: "PHP Group"
kev: false
exploited: false
published: "2024-11-22 07:15:03"
tags: [cve, security, medium]
source: tsecurity.de CVE-Dossier
exported: "2026-09-13T18:12:41+02:00"
---

# CVE-2024-8929

> 5.8 MEDIUM · 🧪 PoC

## Beschreibung

In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, a hostile MySQL server can cause the client to disclose the content of its heap containing data from other SQL requests and possible other data belonging to different users of the same server.

## CVSS-Vektor

```
CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Benachbart | warn |
| AC Komplexität | Hoch | good |
| PR Privilegien | Gering | warn |
| UI Interaktion | Keine | bad |
| S Scope | Verändert | bad |
| C Vertraulichkeit | Hoch | bad |
| I Integrität | Keine | good |
| A Verfügbarkeit | Keine | good |

## Patch verfügbar (OSV)

- 38123aca18c3c1bd1f109ec77af2f175d7afcf35 (Commit)
- a3695d49e878eb2ebbf4645a0975cb5e225fbc7d (Commit)

## Referenzen

- <https://github.com/php/php-src/security/advisories/GHSA-h35g-vwh6-m678>
- <https://lists.debian.org/debian-lts-announce/2024/12/msg00007.html>
- <https://security.netapp.com/advisory/ntap-20250110-0008/>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2024-8929) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
