From 82f480253f6506c241b14a320b2016fc8a058ec2 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 9 Oct 2024 23:54:12 +0000 Subject: [PATCH] Publish GHSA-f3cx-396f-7jqp --- .../GHSA-f3cx-396f-7jqp.json | 35 ++++++++++++++++--- 1 file changed, 31 insertions(+), 4 deletions(-) diff --git a/advisories/github-reviewed/2024/10/GHSA-f3cx-396f-7jqp/GHSA-f3cx-396f-7jqp.json b/advisories/github-reviewed/2024/10/GHSA-f3cx-396f-7jqp/GHSA-f3cx-396f-7jqp.json index 872da46b91b..4af650b0994 100644 --- a/advisories/github-reviewed/2024/10/GHSA-f3cx-396f-7jqp/GHSA-f3cx-396f-7jqp.json +++ b/advisories/github-reviewed/2024/10/GHSA-f3cx-396f-7jqp/GHSA-f3cx-396f-7jqp.json @@ -1,13 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-f3cx-396f-7jqp", - "modified": "2024-10-08T22:19:16Z", + "modified": "2024-10-09T23:52:22Z", "published": "2024-10-08T22:19:16Z", "aliases": [ "CVE-2024-47823" ], "summary": "Livewire Remote Code Execution on File Uploads", - "details": "In livewire/livewire `< v3.5.2`, the file extension of an uploaded file is guessed based on the MIME type. As a result, the actual file extension from the file name is not validated. An attacker can therefore bypass the validation by uploading a file with a valid MIME type (e.g., `image/png`) and a “.php” file extension.\nIf the following criteria are met, the attacker can carry out an RCE attack:\n\n- Filename is composed of the original file name using `$file->getClientOriginalName()`\n- Files stored directly on your server in a public storage disk\n- Webserver is configured to execute “.php” files\n\n### PoC\nIn the following scenario, an attacker could upload a file called `shell.php` with an `image/png` MIME type and execute it on the remote server.\n```php\nclass SomeComponent extends Component\n{\n use WithFileUploads;\n\n #[Validate('image|extensions:png')]\n public $file;\n\n public function save()\n {\n $this->validate();\n\n $this->file->storeAs(\n path: 'images',\n name: $this->file->getClientOriginalName(),\n options: ['disk' => 'public'],\n );\n }\n}\n```\n\n", + "details": "In livewire/livewire prior to `v2.12.7` and `v3.5.2`, the file extension of an uploaded file is guessed based on the MIME type. As a result, the actual file extension from the file name is not validated. An attacker can therefore bypass the validation by uploading a file with a valid MIME type (e.g., `image/png`) and a “.php” file extension.\nIf the following criteria are met, the attacker can carry out an RCE attack:\n\n- Filename is composed of the original file name using `$file->getClientOriginalName()`\n- Files stored directly on your server in a public storage disk\n- Webserver is configured to execute “.php” files\n\n### PoC\nIn the following scenario, an attacker could upload a file called `shell.php` with an `image/png` MIME type and execute it on the remote server.\n```php\nclass SomeComponent extends Component\n{\n use WithFileUploads;\n\n #[Validate('image|extensions:png')]\n public $file;\n\n public function save()\n {\n $this->validate();\n\n $this->file->storeAs(\n path: 'images',\n name: $this->file->getClientOriginalName(),\n options: ['disk' => 'public'],\n );\n }\n}\n```\n\n", "severity": [ { "type": "CVSS_V3", @@ -15,7 +15,7 @@ }, { "type": "CVSS_V4", - "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/" + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N" } ], "affected": [ @@ -29,7 +29,7 @@ "type": "ECOSYSTEM", "events": [ { - "introduced": "0" + "introduced": "3.0.0-beta.1" }, { "fixed": "3.5.2" @@ -37,6 +37,25 @@ ] } ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "livewire/livewire" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "2.12.7" + } + ] + } + ] } ], "references": [ @@ -48,10 +67,18 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47823" }, + { + "type": "WEB", + "url": "https://github.com/livewire/livewire/pull/8624" + }, { "type": "WEB", "url": "https://github.com/livewire/livewire/commit/70503b79f5db75a1eac9bf55826038a6ee5a16d5" }, + { + "type": "WEB", + "url": "https://github.com/livewire/livewire/commit/cd168c6212ea13d13b82b3132485741f82d9fad9" + }, { "type": "PACKAGE", "url": "https://github.com/livewire/livewire"