-
Notifications
You must be signed in to change notification settings - Fork 73
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
CVE-2023-6026 #69
Comments
Do we know if the original 1.2.2 is affected or these are bugs only present in this forked version? Given the severity of these vulnerabilities and lack of response from @elijaa, is it safe to assume this fork is abandoned and should not be used anymore? |
@AlexeyPlodenko Do you want to fix this in your fork perhaps? You didn't enable Issues in your repo so I have to ping you from here. |
Thanks for pining @archon810 |
The issue is resolved in the fork https://github.com/AlexeyPlodenko/phpmemcachedadmin |
Thanks for the quick updates. Will you make an official release (2.0.2?)? Given the lack of POC and details from the CVE writers, how confident are you that you got all of the vulnerabilities? And last question, is the original 1.2.2 release vulnerable too or was it only 1.3's additions that were? |
Briefly looked at the code base. There is at least one more file system related vulnerability. I will check later. Regarding the previous versions. Sorry. No idea. |
Fixed all identified and potential vulnerabilities and drafted a new release - https://github.com/AlexeyPlodenko/phpmemcachedadmin |
This library is not safe to use and probably will not be patched anytime soon.
Reference: https://nvd.nist.gov/vuln/detail/CVE-2023-6026
The text was updated successfully, but these errors were encountered: