HIGH7.8
GHSA-pw5c-xqf2-6xc2
Doctrine Security Misconfiguration Vulnerability
Quick fix
GHSA-pw5c-xqf2-6xc2 — doctrine/annotations: upgrade to the fixed version with the command below.
composer require doctrine/annotations:^1.2.7Details
Doctrine Annotations before 1.2.7, Cache before 1.3.2 and 1.4.x before 1.4.2, Common before 2.4.3 and 2.5.x before 2.5.1, ORM before 2.4.8 or 2.5.x before 2.5.1, MongoDB ODM before 1.0.2, and MongoDB ODM Bundle before 3.0.1 use world-writable permissions for cache directories, which allows local users to execute arbitrary PHP code with additional privileges by leveraging an application with the umask set to 0 and that executes cache entries as code.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/doctrine/annotations
Introduced in:
0Fixed in: 1.2.7Fix
composer require doctrine/annotations:^1.2.7Packagist/doctrine/cache
Introduced in:
1.4.0Fixed in: 1.4.2Fix
composer require doctrine/cache:^1.4.2Packagist/doctrine/common
Introduced in:
2.5.0-stableFixed in: 2.5.1Fix
composer require doctrine/common:^2.5.1Packagist/doctrine/mongodb-odm
Introduced in:
0Fixed in: 1.0.2Fix
composer require doctrine/mongodb-odm:^1.0.2Packagist/doctrine/mongodb-odm-bundle
Introduced in:
0Fixed in: 3.0.1Fix
composer require doctrine/mongodb-odm-bundle:^3.0.1Packagist/zendframework/zendframework1
Introduced in:
1.12.0Fixed in: 1.12.16Fix
composer require zendframework/zendframework1:^1.12.16Packagist/zendframework/zend-cache
Introduced in:
2.5.0Fixed in: 2.5.3Fix
composer require zendframework/zend-cache:^2.5.3Packagist/aws/aws-sdk-php
Introduced in:
3.0.0Fixed in: 3.2.1Fix
composer require aws/aws-sdk-php:^3.2.1Packagist/doctrine/cache
Introduced in:
1.0.0Fixed in: 1.3.2Fix
composer require doctrine/cache:^1.3.2Packagist/zendframework/zend-cache
Introduced in:
2.4.0Fixed in: 2.4.8Fix
composer require zendframework/zend-cache:^2.4.8Packagist/zendframework/zendframework
Introduced in:
2.4.0Fixed in: 2.4.8Fix
composer require zendframework/zendframework:^2.4.8Packagist/zfcampus/zf-apigility-doctrine
Introduced in:
1.0.0Fixed in: 1.0.3Fix
composer require zfcampus/zf-apigility-doctrine:^1.0.3References
- https://nvd.nist.gov/vuln/detail/CVE-2015-5723[ADVISORY]
- https://framework.zend.com/security/advisory/ZF2015-07[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/aws/aws-sdk-php/CVE-2015-5723.yaml[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/doctrine/cache/CVE-2015-5723.yaml[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/doctrine/orm/CVE-2015-5723.yaml[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/zendframework/zend-cache/CVE-2015-5723.yaml[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/zendframework/zendframework/CVE-2015-5723.yaml[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/zendframework/zendframework1/CVE-2015-5723.yaml[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/zfcampus/zf-apigility-doctrine/CVE-2015-5723.yaml[WEB]
- https://github.com/aws/aws-sdk-php/releases/tag/3.2.1[WEB]
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2IUUC7HPN4XE5NNTG4MR76OC662XRZUO[WEB]
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HPS7A54FQ2CR6PH4NDR6UIYJIRNFXW67[WEB]
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2IUUC7HPN4XE5NNTG4MR76OC662XRZUO[WEB]
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HPS7A54FQ2CR6PH4NDR6UIYJIRNFXW67[WEB]
- https://www.doctrine-project.org/2015/08/31/security_misconfiguration_vulnerability_in_various_doctrine_projects.html[WEB]
- http://framework.zend.com/security/advisory/ZF2015-07[WEB]
- http://www.debian.org/security/2015/dsa-3369[WEB]
- http://www.doctrine-project.org/2015/08/31/security_misconfiguration_vulnerability_in_various_doctrine_projects.html[WEB]