CRITICAL9.8
GHSA-vf23-f26f-mjj9
Access of Resource Using Incompatible Type ('Type Confusion') in yourls/yourls
Quick fix
GHSA-vf23-f26f-mjj9 — yourls/yourls: upgrade to the fixed version with the command below.
composer require yourls/yourls:^1.7.4Details
### Impact YOURLS through 1.7.3 is affected by a type juggling vulnerability in the API component that can result in login bypass.
### Patches https://github.com/YOURLS/YOURLS/releases/tag/1.7.4 https://github.com/YOURLS/YOURLS/pull/2542
### References * https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14537 * https://github.com/Wocanilo/CVE-2019-14537
### For more information If you have any questions or comments about this advisory: * Open an issue in [YOURLS repository](https://github.com/YOURLS/YOURLS)
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/YOURLS/YOURLS/security/advisories/GHSA-vf23-f26f-mjj9[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2019-14537[ADVISORY]
- https://github.com/YOURLS/YOURLS/pull/2542[WEB]
- https://github.com/Wocanilo/CVE-2019-14537[WEB]
- https://github.com/YOURLS/YOURLS[PACKAGE]
- https://github.com/YOURLS/YOURLS/commits/master[WEB]
- https://github.com/YOURLS/YOURLS/releases[WEB]
- https://github.com/advisories/GHSA-vf23-f26f-mjj9[ADVISORY]
- https://security-garage.com/index.php/cves/cve-2019-14537-api-authentication-bypass-via-type-juggling[WEB]