VDB
Sign up
HIGH8.8

GHSA-9jxw-cfrh-jxq6

Cachet vulnerable to new line injection during configuration edition

Quick fix

GHSA-9jxw-cfrh-jxq6 — cachethq/cachet: upgrade to the fixed version with the command below.

composer require cachethq/cachet:^2.5.1

Details

### Impact

Authenticated users, regardless of their privileges (_User_ or _Admin_), can exploit a new line injection in the configuration edition feature (e.g. mail settings) and gain arbitrary code execution on the server.

### Patches

This issue was addressed by improving `UpdateConfigCommandHandler` and preventing the use of new lines characters in new configuration values.

### Workarounds

Only allow trusted source IP addresses to access to the administration dashboard.

### References

- https://blog.sonarsource.com/cachet-code-execution-via-laravel-configuration-injection

### For more information

If you have any questions or comments about this advisory, you can contact: - The original reporters, by sending an email to vulnerability.research [at] sonarsource.com; - The maintainers, by opening an issue on this repository.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/cachethq/cachet
Introduced in: 0Fixed in: 2.5.1
Fixcomposer require cachethq/cachet:^2.5.1

References