VDB
Sign up
HIGH8.7

GHSA-8gv3-3j7f-wg94

Potential Remote Code Execution vulnerability

Quick fix

GHSA-8gv3-3j7f-wg94 — nette/application: upgrade to the fixed version with the command below.

composer require nette/application:^2.2.10

Details

Packages nette/application versions prior to 2.2.10, 2.3.14, 2.4.16, 3.0.6 and nette/nette versions prior to 2.0.19 and 2.1.13 are vulnerable to an code injection attack by passing specially formed parameters to URL that may possibly leading to RCE.

Reported by Cyku Hong from DEVCORE (https://devco.re)

### Impact Code injection, possible remote code execution.

### Patches Fixed in nette/application 2.2.10, 2.3.14, 2.4.16, 3.0.6 and nette/nette 2.0.19 and 2.1.13

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/nette/application
Introduced in: 2.2.0Fixed in: 2.2.10
Fixcomposer require nette/application:^2.2.10
Packagist/nette/application
Introduced in: 2.3.0Fixed in: 2.3.14
Fixcomposer require nette/application:^2.3.14
Packagist/nette/application
Introduced in: 2.4.0Fixed in: 2.4.16
Fixcomposer require nette/application:^2.4.16
Packagist/nette/application
Introduced in: 3.0.0Fixed in: 3.0.6
Fixcomposer require nette/application:^3.0.6
Packagist/nette/application
Introduced in: 2.0.0Fixed in: 2.0.19
Fixcomposer require nette/application:^2.0.19
Packagist/nette/application
Introduced in: 2.1.0Fixed in: 2.1.13
Fixcomposer require nette/application:^2.1.13

References