QID 998066
QID 998066: PHP (Composer) Security Update for timber/timber (GHSA-6363-v5m4-fvq3)
Timber is vulnerable to PHAR deserialization due to a lack of checking the input before passing it into the file_exists() function. If an attacker can upload files of any type to the server, he can pass in the phar:// protocol to unserialize the uploaded file and instantiate arbitrary PHP objects. This can lead to remote code execution especially when Timber is used with frameworks with documented POP chains like Wordpress/ vulnerable developer code.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-6363-v5m4-fvq3 for updates and patch information.
Vendor References
- GHSA-6363-v5m4-fvq3 -
github.com/advisories/GHSA-6363-v5m4-fvq3
CVEs related to QID 998066
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-6363-v5m4-fvq3 | timber/timber |
|