CRITICAL9.8
GHSA-2p6p-9rc9-62j9
Craft CMS has potential RCE when PHP `register_argc_argv` config setting is enabled
Quick fix
GHSA-2p6p-9rc9-62j9 — craftcms/cms: upgrade to the fixed version with the command below.
composer require craftcms/cms:^5.5.2Details
### Impact You are affected if your php.ini configuration has `register_argc_argv` enabled.
### Patches Update to 3.9.14, 4.13.2, or 5.5.2.
### Workarounds If you can't upgrade yet, and `register_argc_argv` is enabled, you can disable it to mitigate the issue.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/craftcms/cms
Introduced in:
5.0.0-RC1Fixed in: 5.5.2Fix
composer require craftcms/cms:^5.5.2Packagist/craftcms/cms
Introduced in:
4.0.0-RC1Fixed in: 4.13.2Fix
composer require craftcms/cms:^4.13.2References
- https://github.com/craftcms/cms/security/advisories/GHSA-2p6p-9rc9-62j9[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2024-56145[ADVISORY]
- https://github.com/craftcms/cms/commit/82e893fb794d30563da296bca31379c0df0079b3[WEB]
- https://github.com/Chocapikk/CVE-2024-56145[WEB]
- https://github.com/craftcms/cms[PACKAGE]
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-56145[WEB]