MEDIUM5.8
GHSA-jhm9-h84h-rw83
phpBB Server-Side Request Forgery Vulnerability
Quick fix
GHSA-jhm9-h84h-rw83 — phpbb/phpbb: upgrade to the fixed version with the command below.
composer require phpbb/phpbb:^3.2.10Details
A vulnerability exists in phpBB <v3.2.10 and <v3.3.1 which allowed remote image dimensions check to be used to SSRF.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2020-8226[ADVISORY]
- https://github.com/phpbb/phpbb-app/commit/0cfaaafb386d58576d200d56f1acdbcc2f2376e8[WEB]
- https://github.com/phpbb/phpbb-app/commit/efc0a146bf12125eeb71d00470af774326a7bf0a[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/phpbb/phpbb/CVE-2020-8226.yaml[WEB]
- https://github.com/phpbb/phpbb-app[PACKAGE]
- https://www.phpbb.com/community/viewtopic.php?f=14&t=2562631[WEB]
- https://www.phpbb.com/community/viewtopic.php?f=14&t=2562636[WEB]