GHSA-mm6v-68qp-f9fw
Crayfish allows Remote Code Execution via Homarus Authorization header
Quick fix
GHSA-mm6v-68qp-f9fw — islandora/crayfish: upgrade to the fixed version with the command below.
composer require islandora/crayfish:^4.1.0Details
### Impact
Remote code execution may be possible in web-accessible installations of Homarus in certain configurations.
### Patches
The issue has been patched in `islandora/crayfish:4.1.0`
### Workarounds
The exploit requires making a request against the Homarus's `/convert` endpoint; therefore, the ability to exploit is much reduced if the microservice is not directly accessible from the Internet, so: Prevent general access from the Internet from hitting Homarus.
Configure auth in Crayfish to be more strongly required, such that requests with `Authorization` headers that do not validate are rejected before the problematic CLI interpolation occurs.
### References
- XBOW-024-071
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 4.1.0composer require islandora/crayfish:^4.1.0