Description
In PHP versions 8.1.* before 8.1.28, 8.2.* before 8.2.18, 8.3.* before 8.3.5, when using proc_open() command with array syntax, due to insufficient escaping, if the arguments of the executed command are controlled by a malicious user, the user can supply arguments that would execute arbitrary commands in Windows shell.
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
Low
Affected products
- PHP Group / PHP8.1.* – 8.1.28
- PHP Group / PHP8.2.* – 8.2.18
- PHP Group / PHP8.3.* – 8.3.5
References
- VENDOR_ADVISORYhttps://github.com/php/php-src/security/advisories/GHSA-pc52-254m-w9w7
- MAILING_LISThttp://www.openwall.com/lists/oss-security/2024/04/12/11
- MISChttps://security.netapp.com/advisory/ntap-20240510-0009/
- MAILING_LISThttp://www.openwall.com/lists/oss-security/2024/06/07/1
- MAILING_LISThttps://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PKGTQUOA2NTZ3RXN22CSAUJPIRUYRB4B/
- MAILING_LISThttps://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/W45DBOH56NQDRTOM2DN2LNA2FZIMC3PK/