VDB
Sign up
HIGH8.1

GHSA-cv5c-2qv5-w2m2

Passbolt Api Remote code execution

Quick fix

GHSA-cv5c-2qv5-w2m2 — passbolt/passbolt_api: upgrade to the fixed version with the command below.

composer require passbolt/passbolt_api:^2.7.0

Details

Passbolt provides a way for system administrators to generate a PGP key for the server during installation. The wizard requests a username, an e-mail address and an optional comment. No escaping or verification is done by Passbolt, effectively allowing a user to inject bash code.

The impact is very high, but the probability is very low given that this vulnerability can only be exploited during Passbolt’s installation stage.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/passbolt/passbolt_api
Introduced in: 0Fixed in: 2.7.0
Fixcomposer require passbolt/passbolt_api:^2.7.0

References