Skip to content

Commit f8f4596

Browse files
committed
NEWS
(cherry picked from commit 293cd3b)
1 parent 408692d commit f8f4596

File tree

1 file changed

+2
-0
lines changed

1 file changed

+2
-0
lines changed

NEWS

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -8,6 +8,8 @@ Backported from 8.1.28
88
partial CVE-2022-31629 fix). (CVE-2024-2756) (nielsdos)
99
. Fixed bug GHSA-h746-cjrr-wfmr (password_verify can erroneously return true,
1010
opening ATO risk). (CVE-2024-3096) (Jakub Zelenka)
11+
. Fixed bug GHSA-pc52-254m-w9w7 (Command injection via array-ish $command
12+
parameter of proc_open). (CVE-2024-1874) (Jakub Zelenka)
1113

1214
Backported from 8.0.30
1315

0 commit comments

Comments
 (0)