Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-30287

Опубликовано: 28 июл. 2022
Источник: debian
EPSS Средний

Описание

Horde Groupware Webmail Edition through 5.2.22 allows a reflection injection attack through which an attacker can instantiate a driver class. This then leads to arbitrary deserialization of PHP objects.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
php-horde-turbafixed4.2.25-6package

Примечания

  • https://blog.sonarsource.com/horde-webmail-rce-via-email/

  • https://lists.horde.org/archives/horde/Week-of-Mon-20220530/059225.html

  • Possible alternative patch: https://github.com/horde/turba/pull/7

  • Fixed by: https://github.com/horde/turba/commit/bc53d856ca87656cdc6e5fafd54f2360eb247e24 (v4.2.26)

  • Followup bugfix: https://github.com/horde/turba/commit/006affc530966704937c55611fadb1669026b9f6 (v4.2.27)

  • Fixed by: https://github.com/horde/turba/commit/69f67882539aa0909c3c8c15e37407e0aaa18d1c (v4.2.26)

  • Fixed by: https://github.com/horde/turba/commit/f09285c54673cd3d71d92a8c56da0a2c5ff329ce (v4.2.28)

EPSS

Процентиль: 94%
0.15535
Средний

Связанные уязвимости

CVSS3: 8
ubuntu
больше 3 лет назад

Horde Groupware Webmail Edition through 5.2.22 allows a reflection injection attack through which an attacker can instantiate a driver class. This then leads to arbitrary deserialization of PHP objects.

CVSS3: 8
nvd
больше 3 лет назад

Horde Groupware Webmail Edition through 5.2.22 allows a reflection injection attack through which an attacker can instantiate a driver class. This then leads to arbitrary deserialization of PHP objects.

CVSS3: 8
github
больше 3 лет назад

Horde Groupware Webmail Edition through 5.2.22 allows a reflection injection attack through which an attacker can instantiate a driver class. This then leads to arbitrary deserialization of PHP objects.

CVSS3: 6.3
fstec
больше 3 лет назад

Уязвимость функции create программного средства Horde Webmail, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 94%
0.15535
Средний