CVE-2021-37704
In versions before 6.1.5, 7.1.2, and 8.0.7 the `phpinfo()` can be exposed if the `/vendor` is not protected from public access.
Does this matter?
Lower severity and a low EPSS score (6.13%). Track it; it rarely justifies an emergency change on its own.
Description
PhpFastCache is a high-performance backend cache system (packagist package phpfastcache/phpfastcache). In versions before 6.1.5, 7.1.2, and 8.0.7 the `phpinfo()` can be exposed if the `/vendor` is not protected from public access. This is a rare situation today since the vendor directory is often located outside the web directory or protected via server rule (.htaccess, etc). Only the v6, v7 and v8 will be patched respectively in 8.0.7, 7.1.2, 6.1.5. Older versions such as v5, v4 are not longer supported and will **NOT** be patched. As a workaround, protect the `/vendor` directory from public access.
- CVSS 3.1
- 4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 6.13% probability · 93th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200, CWE-668
- Affected
- phpfastcache/phpfastcache
- Source
- security-advisories@github.com
References
- https://github.com/PHPSocialNetwork/phpfastcache/blob/master/CHANGELOG.md#807Release Notes, Third Party Advisory
- https://github.com/PHPSocialNetwork/phpfastcache/commit/41a77d0d8f126dbd6fbedcd9e6a82e86cdaafa51Patch, Third Party Advisory
- https://github.com/PHPSocialNetwork/phpfastcache/pull/813Patch, Third Party Advisory
- https://github.com/PHPSocialNetwork/phpfastcache/pull/814Third Party Advisory
- https://github.com/PHPSocialNetwork/phpfastcache/pull/815Third Party Advisory
- https://github.com/PHPSocialNetwork/phpfastcache/security/advisories/GHSA-cvh5-p6r6-g2qcThird Party Advisory
- https://github.com/flextype/flextype/issues/567Exploit, Issue Tracking, Third Party Advisory
- https://packagist.org/packages/phpfastcache/phpfastcacheProduct, Third Party Advisory
- https://github.com/PHPSocialNetwork/phpfastcache/blob/master/CHANGELOG.md#807Release Notes, Third Party Advisory
- https://github.com/PHPSocialNetwork/phpfastcache/commit/41a77d0d8f126dbd6fbedcd9e6a82e86cdaafa51Patch, Third Party Advisory
- https://github.com/PHPSocialNetwork/phpfastcache/pull/813Patch, Third Party Advisory
- https://github.com/PHPSocialNetwork/phpfastcache/pull/814Third Party Advisory
- https://github.com/PHPSocialNetwork/phpfastcache/pull/815Third Party Advisory
- https://github.com/PHPSocialNetwork/phpfastcache/security/advisories/GHSA-cvh5-p6r6-g2qcThird Party Advisory
- https://github.com/flextype/flextype/issues/567Exploit, Issue Tracking, Third Party Advisory
- https://packagist.org/packages/phpfastcache/phpfastcacheProduct, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.