Command injection via array-ish $command parameter of proc_open()
Vulnerability Description
In PHP versions 8.1.* before 8.1.28, 8.2.* before 8.2.18, 8.3.* before 8.3.5, when using proc_open() command with array syntax, due to insufficient escaping, if the arguments of the executed command are controlled by a malicious user, the user can supply arguments that would execute arbitrary commands in Windows shell.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-1874
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- RyotaK
References
- https://github.com/php/php-src/security/advisories/GHSA-pc52-254m-w9w7
- http://www.openwall.com/lists/oss-security/2024/04/12/11
- https://security.netapp.com/advisory/ntap-20240510-0009/
- http://www.openwall.com/lists/oss-security/2024/06/07/1
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PKGTQUOA2NTZ3RXN22CSAUJPIRUYRB4B/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/W45DBOH56NQDRTOM2DN2LNA2FZIMC3PK/
More from PHP Group
View All →Affected Vendor
PHP Group
View all reports →