Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE-2023-6026 #69

Open
jorgsowa opened this issue Dec 16, 2023 · 7 comments
Open

CVE-2023-6026 #69

jorgsowa opened this issue Dec 16, 2023 · 7 comments

Comments

@jorgsowa
Copy link

jorgsowa commented Dec 16, 2023

This library is not safe to use and probably will not be patched anytime soon.

A Path traversal vulnerability has been reported in elijaa/phpmemcachedadmin affecting version 1.3.0. This vulnerability allows an attacker to delete files stored on the server due to lack of proper verification of user-supplied input.

Reference: https://nvd.nist.gov/vuln/detail/CVE-2023-6026

@archon810
Copy link

archon810 commented Mar 1, 2024

Do we know if the original 1.2.2 is affected or these are bugs only present in this forked version?

Given the severity of these vulnerabilities and lack of response from @elijaa, is it safe to assume this fork is abandoned and should not be used anymore?

@archon810
Copy link

@AlexeyPlodenko Do you want to fix this in your fork perhaps? You didn't enable Issues in your repo so I have to ping you from here.

https://github.com/AlexeyPlodenko/phpmemcachedadmin

@AlexeyPlodenko
Copy link

Thanks for pining @archon810
I have enabled the Issues page.
Let me take a look on the vulnerability itself.

@AlexeyPlodenko
Copy link

The issue is resolved in the fork https://github.com/AlexeyPlodenko/phpmemcachedadmin

@archon810
Copy link

Thanks for the quick updates. Will you make an official release (2.0.2?)?

Given the lack of POC and details from the CVE writers, how confident are you that you got all of the vulnerabilities?

And last question, is the original 1.2.2 release vulnerable too or was it only 1.3's additions that were?

@AlexeyPlodenko
Copy link

Briefly looked at the code base. There is at least one more file system related vulnerability. I will check later.

Regarding the previous versions. Sorry. No idea.

@AlexeyPlodenko
Copy link

Fixed all identified and potential vulnerabilities and drafted a new release - https://github.com/AlexeyPlodenko/phpmemcachedadmin

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants