GHSA-364w-9g92-3grq
Dashboard / Vulnerabilities / GHSA-364w-9g92-3grq
Summary: Withdrawn: Laravel Framework does not sufficiently block the upload of executable PHP content.
Details: # Withdrawn This advisory has been withdrawn after the maintainers of Laravel noted this issue is not a security vulnerability with Laravel itself, but rather a userland issue. ## Original CVE based description Laravel Framework through 8.70.2 does not sufficiently block the upload of executable PHP content because Illuminate/Validation/Concerns/ValidatesAttributes.php lacks a check for .phar files, which are handled as application/x-httpd-php on systems based on Debian. In some use cases, this may be related to file-type validation for image upload (e.g., differences between getClientOriginalExtension and other approaches).
References: https://nvd.nist.gov/vuln/detail/CVE-2021-43617, https://github.com/laravel/framework, https://github.com/laravel/framework/blob/2049de73aa099a113a287587df4cc522c90961f5/src/Illuminate/Validation/Concerns/ValidatesAttributes.php#L1130-L1132, https://github.com/laravel/framework/blob/2049de73aa099a113a287587df4cc522c90961f5/src/Illuminate/Validation/Concerns/ValidatesAttributes.php#L1331-L1333, https://hosein-vita.medium.com/laravel-8-x-image-upload-bypass-zero-day-852bd806019b, https://salsa.debian.org/php-team/php/-/blob/dc253886b5b2e9bc8d9e36db787abb083a667fd8/debian/php-cgi.conf#L5-6, https://salsa.debian.org/php-team/php/-/commit/dc253886b5b2e9bc8d9e36db787abb083a667fd8
Affected packages
Package
Name: laravel/framework
Purl: pkg:composer/laravel/framework
Affected ranges
Type: ECOSYSTEM
Events:
