CVE-2021-37704

PhpFastCache is a high-performance backend cache system (packagist package phpfastcache/phpfastcache). In versions before 6.1.5, 7.1.2, and 8.0.7 the `phpinfo()` can be exposed if the `/vendor` is not protected from public access. This is a rare situation today since the vendor directory is often located outside the web directory or protected via server rule (.htaccess, etc). Only the v6, v7 and v8 will be patched respectively in 8.0.7, 7.1.2, 6.1.5. Older versions such as v5, v4 are not longer supported and will **NOT** be patched. As a workaround, protect the `/vendor` directory from public access.
References
Link Resource
https://github.com/PHPSocialNetwork/phpfastcache/blob/master/CHANGELOG.md#807 Release Notes Third Party Advisory
https://github.com/PHPSocialNetwork/phpfastcache/commit/41a77d0d8f126dbd6fbedcd9e6a82e86cdaafa51 Patch Third Party Advisory
https://github.com/PHPSocialNetwork/phpfastcache/pull/813 Patch Third Party Advisory
https://github.com/PHPSocialNetwork/phpfastcache/pull/814 Third Party Advisory
https://github.com/PHPSocialNetwork/phpfastcache/pull/815 Third Party Advisory
https://github.com/PHPSocialNetwork/phpfastcache/security/advisories/GHSA-cvh5-p6r6-g2qc Third Party Advisory
https://github.com/flextype/flextype/issues/567 Exploit Issue Tracking Third Party Advisory
https://packagist.org/packages/phpfastcache/phpfastcache Product Third Party Advisory
https://github.com/PHPSocialNetwork/phpfastcache/blob/master/CHANGELOG.md#807 Release Notes Third Party Advisory
https://github.com/PHPSocialNetwork/phpfastcache/commit/41a77d0d8f126dbd6fbedcd9e6a82e86cdaafa51 Patch Third Party Advisory
https://github.com/PHPSocialNetwork/phpfastcache/pull/813 Patch Third Party Advisory
https://github.com/PHPSocialNetwork/phpfastcache/pull/814 Third Party Advisory
https://github.com/PHPSocialNetwork/phpfastcache/pull/815 Third Party Advisory
https://github.com/PHPSocialNetwork/phpfastcache/security/advisories/GHSA-cvh5-p6r6-g2qc Third Party Advisory
https://github.com/flextype/flextype/issues/567 Exploit Issue Tracking Third Party Advisory
https://packagist.org/packages/phpfastcache/phpfastcache Product Third Party Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:phpfastcache:phpfastcache:*:*:*:*:*:*:*:*
cpe:2.3:a:phpfastcache:phpfastcache:*:*:*:*:*:*:*:*
cpe:2.3:a:phpfastcache:phpfastcache:*:*:*:*:*:*:*:*

History

21 Nov 2024, 06:15

Type Values Removed Values Added
CVSS v2 : 4.0
v3 : 4.3
v2 : 4.0
v3 : 5.4
References () https://github.com/PHPSocialNetwork/phpfastcache/blob/master/CHANGELOG.md#807 - Release Notes, Third Party Advisory () https://github.com/PHPSocialNetwork/phpfastcache/blob/master/CHANGELOG.md#807 - Release Notes, Third Party Advisory
References () https://github.com/PHPSocialNetwork/phpfastcache/commit/41a77d0d8f126dbd6fbedcd9e6a82e86cdaafa51 - Patch, Third Party Advisory () https://github.com/PHPSocialNetwork/phpfastcache/commit/41a77d0d8f126dbd6fbedcd9e6a82e86cdaafa51 - Patch, Third Party Advisory
References () https://github.com/PHPSocialNetwork/phpfastcache/pull/813 - Patch, Third Party Advisory () https://github.com/PHPSocialNetwork/phpfastcache/pull/813 - Patch, Third Party Advisory
References () https://github.com/PHPSocialNetwork/phpfastcache/pull/814 - Third Party Advisory () https://github.com/PHPSocialNetwork/phpfastcache/pull/814 - Third Party Advisory
References () https://github.com/PHPSocialNetwork/phpfastcache/pull/815 - Third Party Advisory () https://github.com/PHPSocialNetwork/phpfastcache/pull/815 - Third Party Advisory
References () https://github.com/PHPSocialNetwork/phpfastcache/security/advisories/GHSA-cvh5-p6r6-g2qc - Third Party Advisory () https://github.com/PHPSocialNetwork/phpfastcache/security/advisories/GHSA-cvh5-p6r6-g2qc - Third Party Advisory
References () https://github.com/flextype/flextype/issues/567 - Exploit, Issue Tracking, Third Party Advisory () https://github.com/flextype/flextype/issues/567 - Exploit, Issue Tracking, Third Party Advisory
References () https://packagist.org/packages/phpfastcache/phpfastcache - Product, Third Party Advisory () https://packagist.org/packages/phpfastcache/phpfastcache - Product, Third Party Advisory

Information

Published : 2021-08-12 20:15

Updated : 2024-11-21 06:15


NVD link : CVE-2021-37704

Mitre link : CVE-2021-37704

CVE.ORG link : CVE-2021-37704


JSON object : View

Products Affected

phpfastcache

  • phpfastcache
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

CWE-668

Exposure of Resource to Wrong Sphere