CRITICAL9.8
GHSA-w9ph-q4h9-rwq6
CodeIgniter and Kohana vulnerable to PHP Object Injection
Quick fix
GHSA-w9ph-q4h9-rwq6 — codeigniter/framework: upgrade to the fixed version with the command below.
composer require codeigniter/framework:^3.0.0Details
CodeIgniter before 3.0 and Kohana 3.2.3 and earlier and 3.3.x through 3.3.2 make it easier for remote attackers to spoof session cookies and consequently conduct PHP object injection attacks by leveraging use of standard string comparison operators to compare cryptographic hashes.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/codeigniter/framework
Introduced in:
0Fixed in: 3.0.0Fix
composer require codeigniter/framework:^3.0.0References
- https://nvd.nist.gov/vuln/detail/CVE-2014-8684[ADVISORY]
- https://github.com/kohana/core/pull/492[WEB]
- https://github.com/kohana/core/commit/66b409a6da2960130888989534ff1799532b8f32[WEB]
- https://github.com/bcit-ci/CodeIgniter/blob/2.2.6/system/libraries/Session.php#L159[WEB]
- https://web.archive.org/web/20140802041151/https://scott.arciszewski.me/research/full/php-framework-timing-attacks-object-injection[WEB]
- http://packetstormsecurity.com/files/130609/Seagate-Business-NAS-Unauthenticated-Remote-Command-Execution.html[WEB]
- http://seclists.org/fulldisclosure/2014/May/54[WEB]