QID 996408
Date Published: 2023-12-26
QID 996408: PHP (Composer) Security Update for aws/aws-sdk-php (GHSA-557v-xcg6-rm5m)
Within the scope of requests to S3 object keys and/or prefixes containing a Unix double-dot, a URI path traversal is possible. The issue exists in thebuildEndpoint method in the RestSerializer component of the AWS SDK for PHP v3 prior to 3.288.1. The buildEndpoint method relies on the Guzzle Psr7 UriResolver utility, which strips dot segments from the request path in accordance with RFC 3986. Under certain conditions, this could lead to an arbitrary object being accessed.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-557v-xcg6-rm5m for updates and patch information.
Vendor References
- GHSA-557v-xcg6-rm5m -
github.com/advisories/GHSA-557v-xcg6-rm5m
CVEs related to QID 996408
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-557v-xcg6-rm5m | aws/aws-sdk-php |
|