VDB
Sign up
MEDIUM5.3

GHSA-jg68-vhv3-9r8f

Magento's X-Original-Url header can expose admin url

Quick fix

GHSA-jg68-vhv3-9r8f — openmage/magento-lts: upgrade to the fixed version with the command below.

composer require openmage/magento-lts:^20.16.1

Details

### Impact

The admin url can be discovered without prior knowledge of it's location by exploiting the X-Original-Url header on some configurations.

### Patches

The bug comes from the Zend library and is patche by unsetting the header in the bootstrap process.

### Workarounds

Unset the `X-Original-Url` header in the web server configuration.

### References

The activation of these headers is coming from the Zend_Controller module. It appears this has been known to some degree since 2016 - https://peterocallaghan.co.uk/2016/12/magento-poisoning-cache/ (dead link now..)

### Credit

Anees Hyder ( @anees0xdev ) via HackerOne https://hackerone.com/anees0x_dev/hacktivity

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/openmage/magento-lts
Introduced in: 0Fixed in: 20.16.1
Fixcomposer require openmage/magento-lts:^20.16.1

References