CRITICAL9.8
GHSA-54p5-gxq6-j98g
eZ Publish Kernel and Legacy Unrestricted Upload of File with Dangerous Type
Quick fix
GHSA-54p5-gxq6-j98g — ezsystems/ezpublish-kernel: upgrade to the fixed version with the command below.
composer require ezsystems/ezpublish-kernel:^5.4.14.1Details
eZ Publish Kernel before 5.4.14.1, 6.x before 6.13.6.2, and 7.x before 7.5.6.2 and eZ Publish Legacy before 5.4.14.1, 2017 before 2017.12.7.2, and 2019 before 2019.03.4.2 allow remote attackers to execute arbitrary code by uploading PHP code, unless the vhost configuration permits only app.php execution.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/ezsystems/ezpublish-kernel
Introduced in:
0Fixed in: 5.4.14.1Fix
composer require ezsystems/ezpublish-kernel:^5.4.14.1Packagist/ezsystems/ezpublish-legacy
Introduced in:
0Fixed in: 5.4.14.1Fix
composer require ezsystems/ezpublish-legacy:^5.4.14.1Packagist/ezsystems/ezpublish-kernel
Introduced in:
6.0Fixed in: 6.13.6.2Fix
composer require ezsystems/ezpublish-kernel:^6.13.6.2Packagist/ezsystems/ezpublish-kernel
Introduced in:
7.0Fixed in: 7.5.6.2Fix
composer require ezsystems/ezpublish-kernel:^7.5.6.2Packagist/ezsystems/ezpublish-legacy
Introduced in:
2017Fixed in: 2017.12.7.2Fix
composer require ezsystems/ezpublish-legacy:^2017.12.7.2Packagist/ezsystems/ezpublish-legacy
Introduced in:
2019Fixed in: 2019.03.4.2Fix
composer require ezsystems/ezpublish-legacy:^2019.03.4.2