VDB
Sign up
MEDIUM5.4

GHSA-cvh5-p6r6-g2qc

Exposed phpinfo() leadked via documentation files

Quick fix

GHSA-cvh5-p6r6-g2qc — phpfastcache/phpfastcache: upgrade to the fixed version with the command below.

composer require phpfastcache/phpfastcache:^6.1.5

Details

### Impact The `phpinfo()` can be exposed if the `/vendor` is not protected from public access. This is a rare situation today since the vendor directory is often located outside the web directory or protected via server rule (.htaccess, etc).

### Patches Only the v6, v7 and v8 will be patched respectively in 8.0.7, 7.1.2, 6.1.5. Older versions such as v5, v4 are not longer supported and will **NOT** be patched.

### Workarounds Protect the `/vendor` directory from public access.

### References The first issue revealing this vulnerability is located here: https://github.com/flextype/flextype/issues/567 V6 fix: https://github.com/PHPSocialNetwork/phpfastcache/pull/815 V7 fix: https://github.com/PHPSocialNetwork/phpfastcache/pull/814 V8 fix: https://github.com/PHPSocialNetwork/phpfastcache/pull/813

### For more information If you have any questions or comments about this advisory: * Open an issue in [our issue tracker](https://github.com/PHPSocialNetwork/phpfastcache/issues) * Email us at [security@geolim4.com](mailto:security@geolim4.com)

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/phpfastcache/phpfastcache
Introduced in: 0Fixed in: 6.1.5
Fixcomposer require phpfastcache/phpfastcache:^6.1.5
Packagist/phpfastcache/phpfastcache
Introduced in: 7.0.0Fixed in: 7.1.2
Fixcomposer require phpfastcache/phpfastcache:^7.1.2
Packagist/phpfastcache/phpfastcache
Introduced in: 8.0.0Fixed in: 8.0.7
Fixcomposer require phpfastcache/phpfastcache:^8.0.7

References