VDB
Sign up
CRITICAL9.8

GHSA-54p5-gxq6-j98g

eZ Publish Kernel and Legacy Unrestricted Upload of File with Dangerous Type

Quick fix

GHSA-54p5-gxq6-j98g — ezsystems/ezpublish-kernel: upgrade to the fixed version with the command below.

composer require ezsystems/ezpublish-kernel:^5.4.14.1

Details

eZ Publish Kernel before 5.4.14.1, 6.x before 6.13.6.2, and 7.x before 7.5.6.2 and eZ Publish Legacy before 5.4.14.1, 2017 before 2017.12.7.2, and 2019 before 2019.03.4.2 allow remote attackers to execute arbitrary code by uploading PHP code, unless the vhost configuration permits only app.php execution.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/ezsystems/ezpublish-kernel
Introduced in: 0Fixed in: 5.4.14.1
Fixcomposer require ezsystems/ezpublish-kernel:^5.4.14.1
Packagist/ezsystems/ezpublish-legacy
Introduced in: 0Fixed in: 5.4.14.1
Fixcomposer require ezsystems/ezpublish-legacy:^5.4.14.1
Packagist/ezsystems/ezpublish-kernel
Introduced in: 6.0Fixed in: 6.13.6.2
Fixcomposer require ezsystems/ezpublish-kernel:^6.13.6.2
Packagist/ezsystems/ezpublish-kernel
Introduced in: 7.0Fixed in: 7.5.6.2
Fixcomposer require ezsystems/ezpublish-kernel:^7.5.6.2
Packagist/ezsystems/ezpublish-legacy
Introduced in: 2017Fixed in: 2017.12.7.2
Fixcomposer require ezsystems/ezpublish-legacy:^2017.12.7.2
Packagist/ezsystems/ezpublish-legacy
Introduced in: 2019Fixed in: 2019.03.4.2
Fixcomposer require ezsystems/ezpublish-legacy:^2019.03.4.2

References