According to https://www.php.net/manual/en/security.cgi-bin.force-redirect.php, the configuration directive cgi.force_redirect prevents anyone from calling PHP directly with a URL like http://host.example/cgi-bin/php/secretdir/script.php. The default value of cgi.force_redirect is 1. But there is a bug that can cause attackers to bypass restrictions and access php-cgi directly.
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2024:10952 https://access.redhat.com/errata/RHSA-2024:10952
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2024:10950 https://access.redhat.com/errata/RHSA-2024:10950
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2024:10949 https://access.redhat.com/errata/RHSA-2024:10949
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2024:10951 https://access.redhat.com/errata/RHSA-2024:10951
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2025:7315 https://access.redhat.com/errata/RHSA-2025:7315