VDB
Sign up
HIGH8.8

GHSA-88f9-7xxh-c688

Cachet configuration leak

Quick fix

GHSA-88f9-7xxh-c688 — cachethq/cachet: upgrade to the fixed version with the command below.

composer require cachethq/cachet:^2.5.1

Details

### Impact

Authenticated users, regardless of their privileges (_User_ or _Admin_), can leak the value of any configuration entry of the dotenv file, e.g. the application secret (`APP_KEY`) and various passwords (email, database, etc).

### Patches

This issue was addressed by improving `UpdateConfigCommandHandler` and preventing the use of nested variables in the resulting dotenv configuration file.

### Workarounds

Only allow trusted source IP addresses to access to the administration dashboard.

### References

Further technical details are available at [https://blog.sonarsource.com/cachet-code-execution-via-laravel-configuration-injection](https://blog.sonarsource.com/cachet-code-execution-via-laravel-configuration-injection).

### For more information

If you have any questions or comments about this advisory, you can contact: - The original reporters, by sending an email to vulnerability.research [at] sonarsource.com; - The maintainers, by opening an issue on this repository.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/cachethq/cachet
Introduced in: 0Fixed in: 2.5.1
Fixcomposer require cachethq/cachet:^2.5.1

References