CVE-2019-11831Path Traversal in Pharstreamwrapper

Severity
9.8CRITICALNVD
EPSS
9.7%
top 7.09%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 9
Latest updateSep 30

Description

The PharStreamWrapper (aka phar-stream-wrapper) package 2.x before 2.1.1 and 3.x before 3.1.1 for TYPO3 does not prevent directory traversal, which allows attackers to bypass a deserialization protection mechanism, as demonstrated by a phar:///path/bad.phar/../good.phar URL.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages6 packages

NVDtypo3/pharstreamwrapper2.0.02.1.1+1
Packagisttypo3/phar-stream-wrapper2.0.02.1.1+1
Packagistdrupal/core7.0.07.67.0+2
NVDdrupal/drupal7.07.67+2
Packagistdrupal/drupal7.0.07.67.0+2

Also affects: Debian Linux 8.0, 9.0, Fedora 28, 29, 30

🔴Vulnerability Details

5
GHSA
Directory Traversal in typo3/phar-stream-wrapper2021-09-30
OSV
Directory Traversal in typo3/phar-stream-wrapper2021-09-30
OSV
CVE-2019-11831: The PharStreamWrapper (aka phar-stream-wrapper) package 22019-05-09
CVEList
CVE-2019-11831: The PharStreamWrapper (aka phar-stream-wrapper) package 22019-05-09
OSV
CVE-2019-11831: This security release fixes third-party dependencies included in or required by Drupal core2019-05-08

📋Vendor Advisories

1
Drupal
Drupal core - Moderately critical - Third-party libraries - SA-CORE-2019-0072019-05-08

💬Community

4
Bugzilla
CVE-2019-11830 CVE-2019-11831 php-typo3-phar-stream-wrapper2: various flaws [fedora-all]2019-05-10
Bugzilla
CVE-2019-11831 phar-stream-wrapper: TYP03 does not prevent directory traversal resulting in bypass of deserialization of protection mechanism2019-05-10
Bugzilla
CVE-2019-11830 CVE-2019-11831 php-typo3-phar-stream-wrapper: various flaws [fedora-all]2019-05-10
Bugzilla
CVE-2019-11830 CVE-2019-11831 php-typo3-phar-stream-wrapper2: various flaws [epel-7]2019-05-10
CVE-2019-11831 — Path Traversal in Pharstreamwrapper | cvebase