HIGH8.7
GHSA-8gv3-3j7f-wg94
Potential Remote Code Execution vulnerability
Quick fix
GHSA-8gv3-3j7f-wg94 — nette/application: upgrade to the fixed version with the command below.
composer require nette/application:^2.2.10Details
Packages nette/application versions prior to 2.2.10, 2.3.14, 2.4.16, 3.0.6 and nette/nette versions prior to 2.0.19 and 2.1.13 are vulnerable to an code injection attack by passing specially formed parameters to URL that may possibly leading to RCE.
Reported by Cyku Hong from DEVCORE (https://devco.re)
### Impact Code injection, possible remote code execution.
### Patches Fixed in nette/application 2.2.10, 2.3.14, 2.4.16, 3.0.6 and nette/nette 2.0.19 and 2.1.13
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/nette/application
Introduced in:
2.2.0Fixed in: 2.2.10Fix
composer require nette/application:^2.2.10Packagist/nette/application
Introduced in:
2.3.0Fixed in: 2.3.14Fix
composer require nette/application:^2.3.14Packagist/nette/application
Introduced in:
2.4.0Fixed in: 2.4.16Fix
composer require nette/application:^2.4.16Packagist/nette/application
Introduced in:
3.0.0Fixed in: 3.0.6Fix
composer require nette/application:^3.0.6Packagist/nette/application
Introduced in:
2.0.0Fixed in: 2.0.19Fix
composer require nette/application:^2.0.19Packagist/nette/application
Introduced in:
2.1.0Fixed in: 2.1.13Fix
composer require nette/application:^2.1.13References
- https://github.com/nette/application/security/advisories/GHSA-8gv3-3j7f-wg94[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2020-15227[ADVISORY]
- https://blog.nette.org/en/cve-2020-15227-potential-remote-code-execution-vulnerability[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/nette/application/CVE-2020-15227.yaml[WEB]
- https://github.com/nette/application[PACKAGE]
- https://lists.debian.org/debian-lts-announce/2021/04/msg00003.html[WEB]
- https://packagist.org/packages/nette/application[WEB]
- https://packagist.org/packages/nette/nette[WEB]