MEDIUM4.3
GHSA-4r6g-xhx7-fm36
Contao Core directory traversal vulnerability
Quick fix
GHSA-4r6g-xhx7-fm36 — contao/core: upgrade to the fixed version with the command below.
composer require contao/core:^3.4.4Details
Directory traversal vulnerability in Contao before 3.2.19, and 3.4.x before 3.4.4 allows remote authenticated backend users to view files outside their file mounts or the document root via unspecified vectors.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2015-0269[ADVISORY]
- https://github.com/contao/core/commit/0229e839b4849e402256b972eb62f89f2c29674d[WEB]
- https://contao.org/en/news/contao-3_2_19.html[WEB]
- https://contao.org/en/news/contao-3_4_4.html[WEB]
- https://contao.org/en/news/directory-traversal-vulnerability-cve-2015-0269.html[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/contao/core/CVE-2015-0269.yaml[WEB]
- https://github.com/contao/core[PACKAGE]