CVE-2021-37704
Last modified
CVE-2021-37704 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. PhpFastCache is a high-performance backend cache system (packagist package phpfastcache/phpfastcache). In versions before 6.1.5, 7.1.2, and 8.0.7 the `phpinfo()` can be exposed if the `/vendor` is not protected from public access. EPSS estimates a 6.13% chance of exploitation in the next 30 days.
Description
PhpFastCache is a high-performance backend cache system (packagist package phpfastcache/phpfastcache). In versions before 6.1.5, 7.1.2, and 8.0.7 the `phpinfo()` can be exposed if the `/vendor` is not protected from public access. This is a rare situation today since the vendor directory is often located outside the web directory or protected via server rule (.htaccess, etc). Only the v6, v7 and v8 will be patched respectively in 8.0.7, 7.1.2, 6.1.5. Older versions such as v5, v4 are not longer supported and will **NOT** be patched. As a workaround, protect the `/vendor` directory from public access.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Phpfastcache | Phpfastcache | < 6.1.5 |
| Phpfastcache | Phpfastcache | >= 7.0.0, < 7.1.2 |
| Phpfastcache | Phpfastcache | >= 8.0.0, < 8.0.7 |
References
- https://github.com/PHPSocialNetwork/phpfastcache/blob/master/CHANGELOG.md#807Release Notes, Third Party Advisory
- https://github.com/PHPSocialNetwork/phpfastcache/commit/41a77d0d8f126dbd6fbedcd9e6a82e86cdaafa51Patch, Third Party Advisory
- https://github.com/PHPSocialNetwork/phpfastcache/pull/813Patch, Third Party Advisory
- https://github.com/PHPSocialNetwork/phpfastcache/pull/814Third Party Advisory
- https://github.com/PHPSocialNetwork/phpfastcache/pull/815Third Party Advisory
- https://github.com/flextype/flextype/issues/567Exploit, Issue Tracking, Third Party Advisory
- https://packagist.org/packages/phpfastcache/phpfastcacheProduct, Third Party Advisory
- https://github.com/PHPSocialNetwork/phpfastcache/blob/master/CHANGELOG.md#807Release Notes, Third Party Advisory
- https://github.com/PHPSocialNetwork/phpfastcache/commit/41a77d0d8f126dbd6fbedcd9e6a82e86cdaafa51Patch, Third Party Advisory
- https://github.com/PHPSocialNetwork/phpfastcache/pull/813Patch, Third Party Advisory
- https://github.com/PHPSocialNetwork/phpfastcache/pull/814Third Party Advisory
- https://github.com/PHPSocialNetwork/phpfastcache/pull/815Third Party Advisory
- https://github.com/flextype/flextype/issues/567Exploit, Issue Tracking, Third Party Advisory
- https://packagist.org/packages/phpfastcache/phpfastcacheProduct, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-37704?
How severe is CVE-2021-37704?
How do I fix CVE-2021-37704?
Are you affected by CVE-2021-37704?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
