GHSA-fp63-499m-hq6m
Dashboard / Vulnerabilities / GHSA-fp63-499m-hq6m
Summary: Files or Directories Accessible to External Parties in ether/logs
Details: ### Impact A vulnerability was found that allowed authenticated admin users to access any file on the server. ### Patches The vulnerability has been fixed in 3.0.4. ### Workarounds We recommend disabling the plugin if untrustworthy sources have admin access. ### For more information If you have any questions or comments about this advisory: * Open an issue in [ether/logs](https://github.com/ethercreative/logs/issues)
References: https://github.com/ethercreative/logs/security/advisories/GHSA-fp63-499m-hq6m, https://nvd.nist.gov/vuln/detail/CVE-2021-32752, https://github.com/ethercreative/logs/commit/eb225cc78b1123a10ce2784790f232d71c2066c4, https://github.com/ethercreative/logs/releases/tag/3.0.4
Affected packages
Package
Name: ether/logs
Purl: pkg:composer/ether/logs
Affected ranges
Type: ECOSYSTEM
Events:
