CVE-2023-0567


password_verify() always returns true for some invalid hashes

In PHP 8.0.X before 8.0.28, 8.1.X before 8.1.16 and 8.2.X before 8.2.3, password_verify() function may accept some invalid Blowfish hashes as valid. If such invalid hash ever ends up in the password database, it may lead to an application allowing any password for this entry as valid. 



We have discovered 450,539 live websites that are affected by CVE-2023-0567.

Contact us to get more info




Affected Software

Product  PHP
Category Programming Languages
Vulnerable Versions
  • from 8 before 8.0.28
  • from 8.1 before 8.1.16
  • from 8.2 before 8.2.3
Total Vulnerable Versions507
Vulnerable Domains450,539 live websites (3.72% of PHP install base)


Distribution by Website Rank

The diagram provides a graphic representation of the correlation between the occurrence of CVE-2023-0567 and the relative popularity of websites


Details

  • Published - Feb 16, 2023
  • Updated - Mar 1, 2023

Credits

  • Tim Düsterhus (remediation developer)
  • tech at mkdgs dot fr (finder)




Countries

United States212,620 websites



France80,346 websites
Netherlands16,676 websites
Germany15,251 websites
Russia12,822 websites
Canada11,514 websites
GB10,856 websites
Japan7,257 websites
Italy7,142 websites
Poland6,505 websites

TLDs

.com234,498 websites
.fr35,711 websites
.org29,029 websites
.nl14,068 websites
.net12,717 websites
.ru11,393 websites
.de9,742 websites
.ca7,001 websites
.be6,928 websites
.co.uk6,737 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


Geographical Distribution

The distribution of websites across the globe that are exposed to CVE-2023-0567 through included software libraries and plugins.



References


Websites affected by CVE-2023-0567

Top websites that are affected by CVE-2023-0567. Please click on the "Contact us" button above to get more information.
DomainCountryRankContacts
****.com China*,***
***.****.com China*,***
***************.org United States*,***
******.org United States*,***
********.org United States*,***
***.***************.com Croatia*,***
***************.com Singapore*,***
***.******************.com Singapore*,***
***********************.com United States*,***
*********.ru Russia**,***
See full domain list