VDB
Sign up
MEDIUM

GHSA-mcxr-fx5f-96qq

Server-Side Request Forgery in Concrete CMS

Quick fix

GHSA-mcxr-fx5f-96qq — concrete5/core: upgrade to the fixed version with the command below.

composer require concrete5/core:^8.5.7

Details

Concrete CMS (formerly concrete5) versions below 8.5.7 has a SSRF mitigation bypass using DNS Rebind attack giving an attacker the ability to fetch cloud IAAS (ex AWS) IAM keys.To fix this Concrete CMS no longer allows downloads from the local network and specifies the validated IP when downloading rather than relying on DNS.Discoverer.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/concrete5/core
Introduced in: 0Fixed in: 8.5.7
Fixcomposer require concrete5/core:^8.5.7

References