Описание
Craft CMS has potential RCE when PHP register_argc_argv config setting is enabled
Impact
You are affected if your php.ini configuration has register_argc_argv enabled.
Patches
Update to 3.9.14, 4.13.2, or 5.5.2.
Workarounds
If you can't upgrade yet, and register_argc_argv is enabled, you can disable it to mitigate the issue.
Ссылки
- https://github.com/craftcms/cms/security/advisories/GHSA-2p6p-9rc9-62j9
- https://nvd.nist.gov/vuln/detail/CVE-2024-56145
- https://github.com/craftcms/cms/commit/82e893fb794d30563da296bca31379c0df0079b3
- https://github.com/Chocapikk/CVE-2024-56145
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-56145
Пакеты
craftcms/cms
>= 5.0.0-RC1, < 5.5.2
5.5.2
craftcms/cms
>= 4.0.0-RC1, < 4.13.2
4.13.2
craftcms/cms
>= 3.0.0, < 3.9.14
3.9.14
EPSS
9.3 Critical
CVSS4
9.8 Critical
CVSS3
CVE ID
Дефекты
Связанные уязвимости
Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Users of affected versions are affected by this vulnerability if their php.ini configuration has `register_argc_argv` enabled. For these users an unspecified remote code execution vector is present. Users are advised to update to version 3.9.14, 4.13.2, or 5.5.2. Users unable to upgrade should disable `register_argc_argv` to mitigate the issue.
Уязвимость конфигурации register_argc_argv системы управления контентом Craft CMS, позволяющая нарушителю выполнить произвольный код
EPSS
9.3 Critical
CVSS4
9.8 Critical
CVSS3