VDB
Sign up
HIGH7.2

GHSA-fp63-499m-hq6m

Files or Directories Accessible to External Parties in ether/logs

Quick fix

GHSA-fp63-499m-hq6m — ether/logs: upgrade to the fixed version with the command below.

composer require ether/logs:^3.0.4

Details

### Impact A vulnerability was found that allowed authenticated admin users to access any file on the server.

### Patches The vulnerability has been fixed in 3.0.4.

### Workarounds We recommend disabling the plugin if untrustworthy sources have admin access.

### For more information If you have any questions or comments about this advisory: * Open an issue in [ether/logs](https://github.com/ethercreative/logs/issues)

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/ether/logs
Introduced in: 0Fixed in: 3.0.4
Fixcomposer require ether/logs:^3.0.4

References