Описание
willdurand/js-translation-bundle potential path traversal attack and remote code injection
A path traversal and a javascript code injection vulnerabilities were identified in willdurand/js-translation-bundle versions prior to 2.1.1.
Ссылки
- https://github.com/willdurand/BazingaJsTranslationBundle/commit/7accee93569c3f3d2379f035a41ece66522801fc
- https://github.com/willdurand/BazingaJsTranslationBundle/commit/df6c0fd603c0192ebc5584991a52a1092c5f60bd
- https://github.com/FriendsOfPHP/security-advisories/blob/master/willdurand/js-translation-bundle/2014-07-29-1.yaml
- https://github.com/willdurand/BazingaJsTranslationBundle/releases/tag/v2.1.1
Пакеты
Наименование
willdurand/js-translation-bundle
composer
Затронутые версииВерсия исправления
< 2.1.1
2.1.1
9.8 Critical
CVSS3
Дефекты
CWE-22
CWE-74
9.8 Critical
CVSS3
Дефекты
CWE-22
CWE-74