QID 996069
Date Published: 2023-11-28
QID 996069: PHP (Composer) Security Update for oro/platform (GHSA-9v3j-4j64-p937)
Path Traversal is possible in Oro\Bundle\GaufretteBundle\FileManager::getTemporaryFileName. With this method, an attacker can pass the path to a non-existent file, which will allow writing the content to a new file that will be available during script execution. The file will be deleted immediately after the script ends.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-9v3j-4j64-p937 for updates and patch information.
Vendor References
- GHSA-9v3j-4j64-p937 -
github.com/advisories/GHSA-9v3j-4j64-p937
CVEs related to QID 996069
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-9v3j-4j64-p937 | oro/platform |
|