VDB
Sign up
HIGH8.0

GHSA-x684-96hh-833x

Craft CMS has a potential RCE with a compromised security key

Quick fix

GHSA-x684-96hh-833x — craftcms/cms: upgrade to the fixed version with the command below.

composer require craftcms/cms:^5.5.8

Details

### Impact

This is an RCE vulnerability that affects Craft 4 and 5 installs where your security key has already been compromised.

https://craftcms.com/knowledge-base/securing-craft#keep-your-secrets-secret

Anyone running an unpatched version of Craft with a compromised security key is affected.

### Patches

This has been patched in Craft 5.5.8 and 4.13.8.

### Workarounds

If you can't update to a patched version, then rotating your security key and ensuring its privacy will help to migitgate the issue.

### References

https://github.com/craftcms/cms/commit/e59e22b30c9dd39e5e2c7fe02c147bcbd004e603

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/craftcms/cms
Introduced in: 5.0.0-RC1Fixed in: 5.5.8
Fixcomposer require craftcms/cms:^5.5.8
Packagist/craftcms/cms
Introduced in: 4.0.0-RC1Fixed in: 4.13.8
Fixcomposer require craftcms/cms:^4.13.8

References