Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2rh5-jvgx-pgw3

Опубликовано: 14 сент. 2021
Источник: github
Github: Прошло ревью

Описание

Any storage file can be downloaded from p.sh if full server path is known

The default configuration for platform.sh (.platform.app.yaml) allows access to uploaded files if you know or can guess their location, regardless of whether roles grant content read access to the content containing those files. If you're using Legacy Bridge, the default configuration also allows access to certain legacy files that should not be readable, including the legacy var directory and extension directories.

Пакеты

Наименование

ezsystems/ezplatform

composer
Затронутые версииВерсия исправления

>= 2.0.0, <= 2.5.24

2.5.24.1

Наименование

ezsystems/ezplatform

composer
Затронутые версииВерсия исправления

<= 1.13.6

1.13.6.1

Дефекты

CWE-200

Дефекты

CWE-200