HIGH8.1
GHSA-cv5c-2qv5-w2m2
Passbolt Api Remote code execution
Quick fix
GHSA-cv5c-2qv5-w2m2 — passbolt/passbolt_api: upgrade to the fixed version with the command below.
composer require passbolt/passbolt_api:^2.7.0Details
Passbolt provides a way for system administrators to generate a PGP key for the server during installation. The wizard requests a username, an e-mail address and an optional comment. No escaping or verification is done by Passbolt, effectively allowing a user to inject bash code.
The impact is very high, but the probability is very low given that this vulnerability can only be exploited during Passbolt’s installation stage.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/passbolt/passbolt_api
Introduced in:
0Fixed in: 2.7.0Fix
composer require passbolt/passbolt_api:^2.7.0References
- https://github.com/passbolt/passbolt_api/commit/be84671676ebac43d49e326a14f1afe259777611[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/passbolt/passbolt_api/2019-02-11-1.yaml[WEB]
- https://github.com/passbolt/passbolt_api[PACKAGE]
- https://www.passbolt.com/incidents/20190211_multiple_vulnerabilities[WEB]